CVE-2026-77810
In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.
CSIRTS triage
- What
- Information disclosure vulnerability where Athena Federated Query users with Neptune access can access properties in the Lambda function supplying connector compute.
- Who is affected
- Users with access to Neptune through Athena Federated Query in affected connector versions.
- Urgency
- Important — allows unauthorized access to Lambda function properties and potentially elevated privileges.
- Action
- Upgrade Neptune connector to version greater than v2026.28.1 or before v2024.15.1.
AI-assisted analysis generated from the source advisory — verify against the original.
⚡ Watch CVE-2026-77810
Get an email if CVE-2026-77810 is added to CISA KEV, gains public exploit code, or a new advisory cites it — max one per day, one-click unsubscribe.
Exploitation outlook
- Low exploitation risk0.35% 30-day exploitation probability — currently an unlikely target, but scores change as exploit code circulates. Riskier than 28% of all EPSS-scored CVEs.
Advisory coverage (2)
- criticalCVE-2026-77810: In the Neptune connector, a user with access to Neptune through Athena Federated Query could g…nvd · 2026-08-21
- unknownCVE-2026-77810 - Issue with Athena Federated Query Neptune Connectoraws · 2026-08-21
External references
Embed the live status
— this badge updates automatically when the KEV or exploit status changes. How to embed it →
[](https://www.csirts.com/cve/CVE-2026-77810)