CSIRTS // UNIFIED SECURITY ADVISORY FEEDSYS ● ONLINE · POWERED BY INTELFUSIONS.COM

CVE-2026-12283

mediumCVSS 6.8covered by 2 sourcesfirst seen 2026-07-17
Bulletin ID: 2026-059-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/17/2026 12:00 PM PDT Description: Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. These connectors are open source and deployed to the Athena service on a regular basis. We identified CVE-2026-12283. A user with access to an Azure Synapse account can create a table with a specially crafted name that, when queried through the Athena Synapse connector, could result in unintended data being returned. Impacted versions: - versions >= v2022.20.1 (released on 5/19/2022) AND - versions <= v2026.19.1 (released on 5/28/2026) Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

CSIRTS triage

vendor: Amazonproduct: AthenaInformation disclosureaffected: versions >= v2022.20.1 AND versions <= v2026.19.1
What
A user with access to an Azure Synapse account can create a table with a specially crafted name that may return unintended data when queried through the Athena Synapse connector.
Who is affected
Users with access to an Azure Synapse account using the affected versions of Athena.
Urgency
Remediation is important as it could lead to unintended data exposure, although exploitation has not been reported yet.
Action
Users should update to a version outside the affected range.

AI-assisted analysis generated from the source advisory — verify against the original.

⚡ Watch CVE-2026-12283

Get an email if CVE-2026-12283 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.

Exploitation outlook

Advisory coverage (2)

External references

NVD record for CVE-2026-12283

CVE.org record

Embed the live status

CVE-2026-12283 live status badge — this badge updates automatically when the KEV or exploit status changes. How to embed it →

[![CVE-2026-12283 status](https://www.csirts.com/badge/CVE-2026-12283)](https://www.csirts.com/cve/CVE-2026-12283)