CVE-2026-108096: Improper authorization in query resolvers for SQL-backed models in AWS Amplify API Category

Published Oct 9, 2026
·
Updated

Improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer in AWS Amplify API Category before 3.1.2 might allow an authenticated remote user to read records owned by other users of the same application via crafted queries.

This issue has been addressed in @aws-amplify/graphql-index-transformer 3.1.2 https://www.npmjs.com/package/@aws-amplify/graphql-index-transformer/v/3.1.2 (included in @aws-amplify/data-construct 1.17.4 https://www.npmjs.com/package/@aws-amplify/data-construct/v/1.17.4 and @aws-amplify/graphql-api-construct 1.21.4 https://www.npmjs.com/package/@aws-amplify/graphql-api-construct/v/1.21.4 ). We recommend upgrading to the latest version ensuring any forked or derivative code is patched to incorporate the new fixes and then redeploying their backend.

Affected Software

3 affected components
npm/@aws-amplify/graphql-index-transformer<3.1.2
npm/@aws-amplify/data-construct<1.17.4
npm/@aws-amplify/graphql-api-construct<1.21.4

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade @aws-amplify/graphql-index-transformer to a version that resolves this vulnerability.

    Fixed in 3.1.2
  2. Upgrade

    Upgrade @aws-amplify/data-construct to a version that resolves this vulnerability.

    Fixed in 1.17.4
  3. Upgrade

    Upgrade @aws-amplify/graphql-api-construct to a version that resolves this vulnerability.

    Fixed in 1.21.4
  4. Operational

    Ensure any forked or derivative code incorporates the new fixes, then redeploy the backend.

Event History

Oct 9, 2026
CVE Published
via MITRE·06:10 PM
Data Sourced
via MITRE·06:10 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Applications using AWS Amplify API Category query resolvers generated by @aws-amplify/graphql-index-transformer before 3.1.2 for SQL-backed models are affected. The attacker must be an authenticated user of the same application.

2

What access could an attacker gain?

An authenticated remote attacker could use crafted queries to read records owned by other users in the same application. The provided information describes confidentiality impact only, not modification or availability impact.

3

Which versions include the fix?

The issue is addressed in @aws-amplify/graphql-index-transformer 3.1.2. The fix is also included in @aws-amplify/data-construct 1.17.4 and @aws-amplify/graphql-api-construct 1.21.4.

4

What remediation is required?

Upgrade to a fixed or later version, ensure any forked or derivative code incorporates the fixes, and redeploy the backend.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203