CVE-2026-35560: Improper certificate validation in identity provider connection components in Amazon Athena ODBC driver
Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to connections with external identity providers and does not apply to connections with Athena.
To remediate this issue, users should upgrade to version 2.1.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon Athena ODBC driverto a version that resolves this vulnerability.Fixed in 2.1.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35560?
CVE-2026-35560 has a critical severity rating due to its potential to allow man-in-the-middle attacks.
How do I fix CVE-2026-35560?
To fix CVE-2026-35560, upgrade to the Amazon Athena ODBC Driver version 2.1.0.0 or later.
What systems are affected by CVE-2026-35560?
CVE-2026-35560 affects versions of the Amazon Athena ODBC Driver prior to 2.1.0.0.
What type of vulnerability is CVE-2026-35560?
CVE-2026-35560 is an improper certificate validation vulnerability.
Can CVE-2026-35560 lead to data breaches?
Yes, CVE-2026-35560 can potentially lead to data breaches by allowing attackers to intercept authentication.