CVE-2026-12283 - Issue with Athena Federated Query Synapse Connector
Bulletin ID: 2026-059-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/17/2026 12:00 PM PDT Description: Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. These connectors are open source and deployed to the Athena service on a regular basis. We identified CVE-2026-12283. A user with access to an Azure Synapse account can create a table with a specially crafted name that, when queried through the Athena Synapse connector, could result in unintended data being returned. Impacted versions: - versions >= v2022.20.1 (released on 5/19/2022) AND - versions <= v2026.19.1 (released on 5/28/2026) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- A user with access to an Azure Synapse account can create a table with a specially crafted name that may return unintended data when queried through the Athena Synapse connector.
- Who is affected
- Users with access to an Azure Synapse account using the affected versions of Athena.
- Urgency
- Remediation is important as it could lead to unintended data exposure, although exploitation has not been reported yet.
- Action
- Users should update to a version outside the affected range.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Athena
Get an email when a new Athena advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-059-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-122830.43% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 36% of all scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-12283 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from AWS Security Bulletins
- unknownCVE-2026-18394 - Incorrect authorization in Strands Agents Tools http_request tool2026-07-31
- unknownCVE-2026-18420 - Remote Code Execution via Prototype Pollution in OpenSearch Dashboards TSVB Plugin2026-07-31
- unknownIncomplete fix for CVE-2025-4318 code injection in Amazon @aws-amplify/codegen-ui-react2026-07-31
- unknownCVE-2026-18140 - Uncontrolled recursion in the aws-smithy-json unknown-key skip path allows unauthenticated re…2026-07-31
- unknownCVE-2026-16796 - Improper neutralization of argument delimiters in AWS Bedrock AgentCore Python SDK install_pa…2026-07-23