CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector
Bulletin ID: 2026-087-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 08/21/2026 12:30 PM PDT Description: Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. These connectors are open source and deployed to the Athena service on a regular basis. We identified CVE-2026-77810, in the Neptune connector where a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. Impacted versions: <=v2026.28.1 AND >=v2024.15.1 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
CSIRTS triage
- What
- Information disclosure vulnerability where Athena Federated Query users with Neptune access can access properties in the Lambda function supplying connector compute.
- Who is affected
- Users with access to Neptune through Athena Federated Query in affected connector versions.
- Urgency
- Important — allows unauthorized access to Lambda function properties and potentially elevated privileges.
- Action
- Upgrade Neptune connector to version greater than v2026.28.1 or before v2024.15.1.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch Athena Federated Query Neptune Connector
Get an email when a new Athena Federated Query Neptune Connector advisory drops — max one per day, one-click unsubscribe.
Details
Original advisory: https://aws.amazon.com/security/security-bulletins/rss/2026-087-aws/
Exploitation outlook
EPSS (FIRST.org) estimates each CVE’s probability of exploitation in the next 30 days — here is the CSIRTS.com read on those numbers.
- Low exploitation riskCVE-2026-778100.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
Referenced CVEs
| CVE | CSIRTS overview | External |
|---|---|---|
| CVE-2026-77810 | coverage & exploitation status | NVD · CVE.org |
Same CVEs, other sources
How other CERTs, PSIRTs and databases cover the vulnerabilities in this advisory.
More from AWS Security Bulletins
- unknownCVE-2026-78379 - Consent bypass in Strands Agents Tools python_repl tool2026-08-25
- unknownCVE-2026-77811 - Stored Cross-Site Scripting via Integration Template Asset in OpenSearch Dashboards2026-08-21
- unknownIssue with FreeRTOS-Kernel - CVE-2026-77234, CVE-2026-77235, CVE-2026-77236, CVE-2026-772372026-08-21
- unknownCVE-2026-18830 - Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation2026-08-20
- unknownOngoing updates on Copy.fail and variants2026-08-20