Junglewise Threat Intelligence

CVE-2026-35561: Amazon Athena ODBC driver OS command injection in Linux authentication component

CVE-2026-35561 · Severity: high · CVSS 7.8 · Published 2026-04-03

Technologies: Amazon Athena Odbc, Linux Kernel, Amazon AWS. Vendors: Amazon, Linux, Amazon Web Services.

Executive brief

The Amazon Athena ODBC driver, which allows applications to connect to the Athena data analysis service, contains a security flaw in its Linux version. An attacker could use specially crafted connection settings to trick a user into running malicious commands on their computer. This could lead to a full system compromise, unauthorized data access, or the installation of malware when a user attempts to connect to a database.

Technical details

An OS command injection vulnerability exists in the browser-based authentication component of the Amazon Athena ODBC driver for Linux. The flaw is rooted in the improper neutralization of special elements within connection parameters that are processed when the driver launches a browser for authentication. A local attacker can exploit this by providing specially crafted connection strings; when a user initiates a connection using these parameters, the driver executes arbitrary shell commands with the privileges of the local user. This issue was specifically addressed by improving the browser launch mechanism to use safer system APIs. Users should upgrade to version 2.0.5.1 or later to remediate this vulnerability.

Affected products

  • Amazon Amazon Athena ODBC driver < 2.0.5.1 (Linux)

CVE identifiers

  • CVE-2026-35561
  • CVE-2026-35558
  • CVE-2026-35562
  • CVE-2026-5485
  • CVE-2026-35560
  • CVE-2026-35559

Timeline

  • 2025-10-13: patched: Version 2.0.5.1 released to address the Linux-specific injection issue.
  • 2026-03-20: advisory: Version 2.1.0.0 released with broader security improvements.
  • 2026-04-03: disclosed: CVE-2026-5485 published.

References

Related threats