Junglewise Threat Intelligence

CVE-2026-35560: Amazon Athena ODBC driver improper certificate validation in IdP connection

CVE-2026-35560 · Severity: high · CVSS 7.4 · Published 2026-04-03

Technologies: Amazon Athena Odbc, Apple macOS, Microsoft Windows, Linux Kernel. Vendors: Amazon, Apple, Microsoft, Linux.

Executive brief

The Amazon Athena ODBC driver, which allows applications to connect to and query data in Amazon Athena, contained a security flaw in how it verified identity provider certificates. An attacker positioned on the network could exploit this to intercept sensitive authentication credentials when the driver connects to external login services. This could lead to unauthorized access to corporate data or cloud environments.

Technical details

A vulnerability classified as Improper Certificate Validation (CWE-295) exists in the identity provider connection components of the Amazon Athena ODBC driver. The driver failed to enforce sufficient default transport security, specifically neglecting to validate the SSL certificates of external identity providers (IdPs) during the authentication flow. A network-positioned attacker capable of intercepting traffic (Man-in-the-Middle) could present a spoofed certificate to capture authentication credentials. This issue affects connections to external IdPs but does not impact direct connections to the Athena service itself. The vulnerability is remediated in version 2.1.0.0, which enables SSL certificate validation by default and enforces a minimum of TLS 1.2.

Affected products

  • Amazon Athena ODBC driver versions before 2.1.0.0

Timeline

  • 2026-03-20: patched: Version 2.1.0.0 released with fix.
  • 2026-04-03: disclosed: Initial publication of CVE-2026-35560.
  • 2026-04-03: advisory: AWS Security Bulletin 2026-013-AWS published.

References

Related threats