CVE-2026-5485: OS command injection in Amazon Athena ODBC driver on Linux
OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded by the driver during a local user-initiated connection.
To remediate this issue, users should upgrade to version 2.0.5.1 or later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Amazon Athena ODBC driver (Linux)to a version that resolves this vulnerability.Fixed in 2.0.5.1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-5485?
The severity of CVE-2026-5485 is considered high due to the potential for arbitrary code execution.
How do I fix CVE-2026-5485?
To fix CVE-2026-5485, upgrade to the Amazon Athena ODBC driver version 2.0.5.1 or later.
What is affected by CVE-2026-5485?
CVE-2026-5485 affects the Amazon Athena ODBC driver on Linux versions prior to 2.0.5.1.
Can CVE-2026-5485 lead to data breaches?
Yes, CVE-2026-5485 can potentially lead to data breaches by allowing unauthorized code execution.
What is an OS command injection in context of CVE-2026-5485?
OS command injection in CVE-2026-5485 occurs when crafted connection parameters enable execution of arbitrary commands on the system.