Junglewise Threat Intelligence

CVE-2026-35561: Amazon Athena ODBC driver insufficient authentication controls

CVE-2026-35561 · Severity: high · CVSS 7.4 · Published 2026-04-03

Technologies: Amazon Athena Odbc, Apple macOS, Microsoft Windows, Linux Kernel. Vendors: Amazon, Apple, Microsoft, Linux.

Executive brief

The Amazon Athena ODBC driver, which allows applications to connect to and query data in Amazon Athena, contains a security flaw in its browser-based login process. An attacker could potentially intercept or hijack a user's authentication session, leading to unauthorized access to data and resources. This issue affects users on Windows, Linux, and macOS who use browser-based login methods.

Technical details

The Amazon Athena ODBC driver prior to version 2.1.0.0 suffers from missing authorization and session security controls (CWE-862) within its browser-based authentication plugins (BrowserSSOOIDC, BrowserAzureAD, and BrowserSAML). Specifically, the driver lacked PKCE (Proof Key for Code Exchange) for OAuth flows and RelayState CSRF protection for SAML, making it vulnerable to authorization code interception and SAML token injection attacks. An unauthenticated remote attacker could exploit these weaknesses to hijack authentication sessions. The vulnerability is resolved in version 2.1.0.0, which migrates to Authorization Code with PKCE, implements CSRF protections, and enforces stricter TLS 1.2+ requirements.

Affected products

  • Amazon Amazon Athena ODBC driver < 2.1.0.0

Timeline

  • 2026-03-20: patched: Version 2.1.0.0 released
  • 2026-04-03: disclosed: Initial advisory published by Amazon
  • 2026-04-03: advisory: NVD entry created

References

Related threats