CVE-2026-105811: Authorization bypass through a user-controlled key in the Amazon Q Business Lambda hook sample in QnABot on AWS
Authorization bypass through a user-controlled key in the optional Amazon Q Business Lambda hook sample ( q-business-lambda-hook https://github.com/aws-solutions-library-samples/qnabot-on-aws/blob/main/source/docs/lambdahooks/README.md ), available with QnABot on AWS versions 7.0.0 through 7.4.5, might allow an authenticated remote user to read arbitrary Amazon S3 objects in the deploying AWS account. This sample solution provides an example Lambda hook and requires separate, manual deployment and additional setup. It is not deployed automatically with QnABot. Customers who have not deployed this optional sample hook are not affected and do not need to take action.
To remediate this issue, affected customers should update the QnABot on AWS stack to version 7.4.6 or later and then redeploy the Amazon Q Business Lambda hook sample stack. Updating the QnABot on AWS stack alone does not deliver the fix.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
QnABot on AWSto a version that resolves this vulnerability.Fixed in 7.4.6 - Operational
After updating the QnABot on AWS stack, redeploy the Amazon Q Business Lambda hook sample stack; updating QnABot alone does not deliver the fix.
Event History
Frequently Asked Questions
Who is affected by this issue?
Only deployments that separately and manually deployed the optional Amazon Q Business Lambda hook sample are affected. QnABot on AWS deployments that did not deploy this sample hook are not affected and do not need to take action.
What access does an attacker need to exploit the issue?
An attacker must be an authenticated remote user. Successful exploitation could allow that user to read arbitrary Amazon S3 objects in the AWS account that deployed the affected hook.
Is updating the QnABot on AWS stack sufficient to remediate the issue?
No. Affected customers must update the QnABot on AWS stack to version 7.4.6 or later and then redeploy the Amazon Q Business Lambda hook sample stack; updating QnABot alone does not deliver the fix.