CVE-2026-75910: Incorrect privilege assignment in the Amazon aws-athena-query-federation ClickHouse connector deployment template

Published Aug 20, 2026
·
Updated

Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at a database endpoint under the user's control, causing the connector to transmit the secret to that endpoint. To remediate this issue, users should upgrade to aws-athena-query-federation connectors version v2026.17.1 or later and ensure that any forked or derivative code is patched to incorporate the new fixes. Alternatively, to remediate this issue, users should redeploy the connector with the current template and supply a non-empty SecretNamePrefix value.

Affected Software

1 affected component
aws-athena-query-federation ClickHouse connector<v2026.17.1

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade Amazon aws-athena-query-federation ClickHouse connector to a version that resolves this vulnerability.

    Fixed in v2026.17.1
  2. Compensating control

    If you use forked or derivative connector code, ensure it is patched to incorporate the v2026.17.1 fixes.

  3. Operational

    Redeploy the connector using the current deployment template and supply a non-empty SecretNamePrefix value.

Event History

Aug 20, 2026
CVE Published
via MITRE·08:06 PM
Data Sourced
via MITRE·08:06 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who is exposed to this issue?

Deployments of the Amazon Athena Federated Query ClickHouse connector using a version prior to v2026.17.1 are affected. Forked or derivative connector code also needs the corresponding fixes applied.

2

What does an attacker need to exploit it?

The attacker must be an authenticated remote user. They need to point the connector at an unrelated AWS Secrets Manager secret and use a database endpoint under their control, which can receive the transmitted secret.

3

What should be done if an immediate version upgrade is not possible?

Redeploy the connector using the current deployment template and provide a non-empty SecretNamePrefix value. This is an alternative remediation to upgrading to v2026.17.1 or later.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203