Junglewise Threat Intelligence

CVE-2026-77810: AWS Athena Federated Query Neptune Connector credential exposure

CVE-2026-77810 · Severity: high · Published 2026-09-09

Executive brief

AWS Athena's Neptune connector is a cloud service that allows users to query graph database data through standard SQL. A flaw in this connector allows anyone with Neptune query access to extract sensitive configuration and credential information from the underlying cloud infrastructure that runs the connector. This could enable attackers to gain deeper access to cloud resources and bypass security controls.

Technical details

CVE-2026-77810 is an information disclosure vulnerability in the AWS Athena Federated Query Neptune connector (versions >=v2024.15.1 and <=v2026.28.1). The vulnerability allows an authenticated user with Neptune query access to extract properties and secrets from the Lambda execution environment that supplies compute for the connector. The attack requires user access to Neptune through Athena Federated Query; no additional network access or code injection is needed. An attacker can leverage this to obtain Lambda environment variables, function configuration, and potentially IAM credentials, leading to further cloud resource compromise. AWS has patched this issue in versions after v2026.28.1.

Affected products

  • Amazon Athena Federated Query Neptune Connector >=v2024.15.1, <=v2026.28.1

Timeline

  • 2026-09-09: disclosed: CVE published and security bulletin issued
  • 2026-08-21: advisory: AWS Security Bulletin 2026-087-AWS published

References

Related threats