CVE-2026-108096: Improper authorization in query resolvers for SQL-backed models in AWS Amplify API Category
Improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer in AWS Amplify API Category before 3.1.2 might allow an authenticated remote user to read records owned by other users of the same application via crafted queries.
This issue has been addressed in @aws-amplify/graphql-index-transformer 3.1.2 https://www.npmjs.com/package/@aws-amplify/graphql-index-transformer/v/3.1.2 (included in @aws-amplify/data-construct 1.17.4 https://www.npmjs.com/package/@aws-amplify/data-construct/v/1.17.4 and @aws-amplify/graphql-api-construct 1.21.4 https://www.npmjs.com/package/@aws-amplify/graphql-api-construct/v/1.21.4 ). We recommend upgrading to the latest version ensuring any forked or derivative code is patched to incorporate the new fixes and then redeploying their backend.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
@aws-amplify/graphql-index-transformerto a version that resolves this vulnerability.Fixed in 3.1.2 - Upgrade
Upgrade
@aws-amplify/data-constructto a version that resolves this vulnerability.Fixed in 1.17.4 - Upgrade
Upgrade
@aws-amplify/graphql-api-constructto a version that resolves this vulnerability.Fixed in 1.21.4 - Operational
Ensure any forked or derivative code incorporates the new fixes, then redeploy the backend.
Event History
Frequently Asked Questions
Who is exposed to this issue?
Applications using AWS Amplify API Category query resolvers generated by @aws-amplify/graphql-index-transformer before 3.1.2 for SQL-backed models are affected. The attacker must be an authenticated user of the same application.
What access could an attacker gain?
An authenticated remote attacker could use crafted queries to read records owned by other users in the same application. The provided information describes confidentiality impact only, not modification or availability impact.
Which versions include the fix?
The issue is addressed in @aws-amplify/graphql-index-transformer 3.1.2. The fix is also included in @aws-amplify/data-construct 1.17.4 and @aws-amplify/graphql-api-construct 1.21.4.
What remediation is required?
Upgrade to a fixed or later version, ensure any forked or derivative code incorporates the fixes, and redeploy the backend.