Junglewise Threat Intelligence

CVE-2026-11400: AWS Advanced JDBC Wrapper privilege escalation in GlobalDatabasePlugin

CVE-2026-11400 · Severity: high · CVSS 8 · Published 2026-06-05

Technologies: Amazon AWS. Vendors: Amazon, Amazon Web Services, Maven.

Executive brief

AWS Aurora PostgreSQL databases can be compromised through privilege escalation vulnerabilities in the Advanced JDBC Wrapper and Advanced Go Wrapper libraries. An attacker who gains access to a database connection can escalate their privileges to gain unauthorized access to sensitive data or perform unauthorized administrative operations, potentially affecting the confidentiality and integrity of customer databases.

Technical details

These vulnerabilities exist in AWS Advanced JDBC Wrapper and Advanced Go Wrapper libraries used to connect to Aurora PostgreSQL databases. The vulnerabilities enable privilege escalation, allowing an attacker who has established a database connection to escalate their user privileges beyond their intended authorization level. Attack preconditions require the attacker to have initial access to establish a database connection. The specific root cause and vulnerable components are not detailed in the available reference material. AWS has issued security advisories (CVE-2026-11400 and CVE-2026-11401) addressing these issues. Patches or mitigations should be obtained from the AWS security bulletins.

Affected products

  • Amazon Web Services Aurora PostgreSQL <UNKNOWN>
  • Amazon Web Services AWS Advanced JDBC Wrapper <UNKNOWN>
  • Amazon Web Services AWS Advanced Go Wrapper <UNKNOWN>

Timeline

  • 2026-09-22: disclosed: Vulnerability disclosed via AWS security bulletin

References

Related threats