CVE-2026-35561: Insufficient authentication security controls in browser-based authentication components in Amazon Athena ODBC driver
Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-based authentication flows.
To remediate this issue, users should upgrade to version 2.1.0.0.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon Athena ODBC driverto a version that resolves this vulnerability.Fixed in 2.1.0.0
Event History
Frequently Asked Questions
What is the severity of CVE-2026-35561?
CVE-2026-35561 is considered a high severity vulnerability due to insufficient authentication security controls.
How do I fix CVE-2026-35561?
To resolve CVE-2026-35561, update the Amazon Athena ODBC driver to version 2.1.0.0 or later.
What components are affected by CVE-2026-35561?
CVE-2026-35561 affects the browser-based authentication components in the Amazon Athena ODBC driver before version 2.1.0.0.
Can CVE-2026-35561 lead to data interception?
Yes, CVE-2026-35561 may allow threat actors to intercept authentication data if not addressed.
Is CVE-2026-35561 specific to a particular operating system?
CVE-2026-35561 is related to the Amazon Athena ODBC driver and is not specific to any operating system.