CVE-2026-94384: Missing Authorization in sfExecuteAWSService Lambda Dispatcher in Amazon Connect Salesforce Lambda

Published Sep 22, 2026
·
Updated

Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API operations that their own IAM identity is explicitly denied, via invocation of a Lambda function that dispatches caller-supplied parameters to privileged service APIs without authorization validation.

To remediate this issue, we recommend upgrading to version 5.26 or later. After setup is complete, either delete or disable the sfExecuteAWSService function. If you retain the function, restrict invocation to the intended IAM user only.

Affected Software

1 affected component
Amazon Amazon Connect Salesforce Lambda<5.26

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade amazon-connect-salesforce-lambda to a version that resolves this vulnerability.

    Fixed in 5.26
  2. Configuration

    After setup is complete, disable sfExecuteAWSService; alternatively, delete the function.

    sfExecuteAWSService Lambda function enabled = false
  3. Compensating control

    If sfExecuteAWSService is retained, restrict invocation to the intended IAM user only.

Event History

Sep 22, 2026
CVE Published
via MITRE·05:07 PM
Data Sourced
via MITRE·05:07 PM
DescriptionSeverityWeakness
Data Sourced
via NVD·06:17 PM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

Any IAM principal that has lambda:InvokeFunction permission on the affected sfExecuteAWSService function can exploit it. The caller does not need IAM permission for the AWS API operations performed through the function.

2

Are deployments using the default configuration affected?

No. The sfExecuteAWSService function is disabled by default.

3

What should be done if the function is not required?

After upgrading to version 5.26 or later, delete or disable sfExecuteAWSService. This removes the exposed dispatcher.

4

What mitigation is available if sfExecuteAWSService must be retained?

Restrict invocation of the function to the intended IAM user only. Do not allow other IAM principals to invoke it.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203