Executive brief
The DuckDB AWS extension includes a function that allows database users to extract plaintext AWS authentication credentials, bypassing the database's intended security policy that should redact sensitive secrets. An attacker with database access can call a single function to retrieve active AWS credentials that are immediately usable against cloud infrastructure, particularly dangerous in cloud environments where the database automatically inherits credentials from the hosting platform.
Technical details
The vulnerability is a security policy bypass in the `load_aws_credentials()` function within the DuckDB AWS extension. The function accepts a `redact_secret` parameter that, when set to false, returns plaintext AWS credentials (access_key_id, secret_access_key, session_token, region) despite the database-wide `allow_unredacted_secrets=false` policy. Any database user with SQL execution permissions can invoke this function to circumvent the policy. The attack requires only SQL execution access—no additional network or privilege escalation is needed. Affected credentials may include temporary credentials from AWS credential chains (IMDSv2, IRSA, ECS task roles, EC2 instance roles) in managed deployment scenarios. The vulnerability was addressed by removing the deprecated `load_aws_credentials()` function entirely in a June 2026 commit.
Affected products
- DuckDB AWS extension <1.0.0 (prior to June 23, 2026 patch)
Timeline
- 2026-08-03: disclosed: CVE-2026-58139 published
- 2026-06-23: patched: Function removed via commit 7d04119