Junglewise Threat Intelligence

CVE-2026-35558: Amazon Athena ODBC driver command injection in authentication components

CVE-2026-35558 · Severity: high · CVSS 7.8 · Published 2026-04-03

Technologies: Amazon Athena Odbc, Apple macOS, Microsoft Windows, Linux Kernel. Vendors: Amazon, Apple, Microsoft, Linux.

Executive brief

The Amazon Athena ODBC driver is a software component that allows various applications to connect to and query data stored in Amazon Athena. A security vulnerability in the driver's authentication components could allow an attacker to execute unauthorized code or redirect login attempts by tricking a user into using malicious connection settings. This could lead to a full system compromise or the theft of sensitive credentials.

Technical details

A command injection vulnerability (CWE-77) exists in the authentication components of the Amazon Athena ODBC driver, specifically affecting the BrowserSSOOIDC, BrowserAzureAD, and BrowserSAML plugins. The flaw stems from improper neutralization of special elements within connection parameters processed during user-initiated authentication. An attacker can exploit this by providing specially crafted connection strings that, when processed by the driver, lead to arbitrary code execution or the redirection of authentication flows. The vulnerability is addressed in version 2.1.0.0, which implements improved input validation and security controls such as PKCE for OAuth flows.

Affected products

  • Amazon Amazon Athena ODBC driver versions before 2.1.0.0

Timeline

  • 2026-03-20: patched: Version 2.1.0.0 released with security fixes.
  • 2026-04-03: disclosed: Initial advisory publication.

References

Related threats