Sceawere

Vulnerability Detail

CVE-2026-75910UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Amazon Athena ClickHouse Connector Privilege Assignment Vulnerability

Vulnerability Metadata

Severity
Medium
Score / CVSS
6.5
Creation Date
4h ago
Vendor
AWS
Product
Athena Federated Query Clickhouse Connector deployment template
Attack Type
CWE-266 Incorrect privilege assignment
Vector String
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at a database endpoint under the user's control, causing the connector to transmit the secret to that endpoint. To remediate this issue, users should upgrade to aws-athena-query-federation connectors version v2026.17.1 or later and ensure that any forked or derivative code is patched to incorporate the new fixes. Alternatively, to remediate this issue, users should redeploy the connector with the current template and supply a non-empty SecretNamePrefix value.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "6.5",
  "pubDate": "2026-08-20T20:17:46.937Z",
  "pubdate": "2026-08-20T20:17:46.937Z",
  "executiveSummary": "An incorrect privilege assignment vulnerability exists within the ClickHouse connector deployment template in Amazon Athena Federated Query prior to version v2026.17.1. This security flaw allows an authenticated remote user to read arbitrary AWS Secrets Manager secrets residing within the deploying account. The vulnerability stems from improper handling of connection parameters and secret resolution during connector deployment, enabling unauthorized data exfiltration. Successful exploitation leads to the unauthorized disclosure of sensitive credentials or configuration data stored in AWS Secrets Manager. The attack requires authenticated remote access and the ability to configure or point the connector's connection string to a controlled database endpoint and an unrelated secret. Risk implications include severe confidentiality breaches within the affected cloud environment. Remediation requires upgrading the aws-athena-query-federation connectors to version v2026.17.1 or later, patching any derivative codebases, or redeploying the affected connector using the updated template with a non-empty SecretNamePrefix value.",
  "technicalDetails": "The vulnerability resides in the ClickHouse connector deployment template utilized within Amazon Athena Federated Query prior to version v2026.17.1. The root cause is rooted in an incorrect privilege assignment configuration that improperly restricts or validates the scope of secrets requested and resolved by the connector during initialization or execution phases. Specifically, the vulnerable component fails to enforce strict boundaries on AWS Secrets Manager secret references mapped through the connector's connection string.\nExploitation of this vulnerability requires an authenticated remote user with the capability to supply or modify connection parameters for the deployed ClickHouse connector. The attack flow proceeds as follows: First, the malicious or unauthorized user points the connector's connection string to reference an unrelated, highly sensitive AWS Secrets Manager secret within the deploying account. Second, the user directs the connector to establish a connection with a remote database endpoint entirely under the attacker's administrative control. Third, upon initialization and execution, the connector attempts to resolve the specified secret from AWS Secrets Manager utilizing its assigned execution role permissions. Finally, the connector inadvertently transmits the retrieved secret payload directly to the attacker-controlled database endpoint, resulting in successful data exfiltration.\nThe affected versions include all aws-athena-query-federation connectors prior to v2026.17.1. Network exposure involves the connector runtime environment interacting with AWS Secrets Manager and external database endpoints. Authentication and privilege requirements mandate that the initiating actor is an authenticated user capable of manipulating connection strings or deployment parameters, leveraging the over-privileged execution context of the connector to access arbitrary secrets."
}
CVE-2026-75910: Amazon Athena ClickHouse Connector Privilege Assignment Vulnerability (MEDIUM Severity, CVSS: 6.5) - Sceawere