Junglewise Threat Intelligence

CVE-2026-90513: simalexan api-lambda-send-email-ses authentication bypass in API Gateway

CVE-2026-90513 · Severity: medium · CVSS 6.5 · Published 2026-09-13

Executive brief

A serverless email service on AWS Lambda lacks authentication on its public API endpoint, allowing unauthenticated users to trigger arbitrary emails through Amazon SES. An attacker can submit malicious email content (including HTML), potentially causing resource abuse, operational costs, phishing campaigns, or service disruption by sending unsolicited emails from your configured identity.

Technical details

The vulnerability is a missing authentication (auth bypass) flaw in the SAM/CloudFormation template for the API Gateway POST /send endpoint. The Lambda function accepts caller-controlled email parameters (toEmails, ccEmails, replyToEmails, subject, message) and forwards them directly to AWS SES via the Lambda execution role's SESCrudPolicy without validating the caller identity, enforcing rate limits, or validating input format. An unauthenticated remote attacker can invoke this endpoint if the API URL is known, causing the Lambda execution role to invoke SES.sendEmail() with arbitrary subject and message content (including HTML). The impact is bounded by SES IAM/identity constraints (verified senders only), but attackers can exhaust resources, generate costs, and conduct phishing within those constraints. No authentication, authorizer, usage plan, or WAF protection is configured. A fix requires adding Cognito/Lambda/IAM authorizers to the API Gateway event definition and implementing input validation and rate limiting.

Affected products

  • simalexan api-lambda-send-email-ses up to bda6869aa81371d1e872242e74fe7d953edb818d

Timeline

  • 2026-06-30: disclosed: Issue #9 filed on GitHub
  • 2026-09-13: advisory: CVE-2026-90513 published

References