CVE-2026-35558: Improper neutralization of special elements in authentication components in Amazon Athena ODBC driver
Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection parameters that are processed by the driver during user-initiated authentication.
To remediate this issue, users should upgrade to version 2.1.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon Athena ODBC driverto a version that resolves this vulnerability.Fixed in 2.1.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35558?
CVE-2026-35558 has a high severity rating due to its potential for arbitrary code execution.
How do I fix CVE-2026-35558?
To fix CVE-2026-35558, update to the Amazon Athena ODBC driver version 2.1.0.0 or later.
What components are affected by CVE-2026-35558?
CVE-2026-35558 affects the authentication components of the Amazon Athena ODBC driver before version 2.1.0.0.
Can CVE-2026-35558 lead to data breaches?
Yes, if exploited, CVE-2026-35558 can allow a threat actor to execute arbitrary code possibly leading to data breaches.
Is CVE-2026-35558 specific to any operating system?
No, CVE-2026-35558 is not limited to a specific operating system but affects the Amazon Athena ODBC driver across multiple platforms.