CVE-2026-77810: Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
aws-athena-query-federationto a version that resolves this vulnerability.Fixed in v2026.30.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An attacker needs access to Neptune through Athena Federated Query. The issue affects the Neptune connector in aws-athena-query-federation.
What could an attacker gain through successful exploitation?
A user with the required Athena Federated Query access could gain access to properties in the Lambda that supplies compute for the connector.
How should this be remediated?
Upgrade aws-athena-query-federation to version 2026.30.1 or later.