216.73.216.6

CVE-2026-35561

· Published 03/04/2026 21:17 · Modified 03/04/2026 21:17

Labels: CVE-2026-35561 2026-04-03CVE-2026-35561CWE-862ff89ba41-3aa1-4d27-914a-91399e9639e5

Essential information

Published
03/04/2026 21:17
Modified
03/04/2026 21:17
Author
Creator
CVSS
9.1 CRITICAL (v3) 9.1 CRITICAL (v4.0)
CISA KEV
No
CWE
CVSS vector

CVSS metrics

Description

Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-based authentication flows. To remediate this issue, users should upgrade to version 2.1.0.0.

NVD status

Status
Received — CVE has been recently published to the CVE List and has been received by the NVD.
Source
ff89ba41-3aa1-4d27-914a-91399e9639e5
NVD
View on NVD

Affected products (CPE)

ProductCPE
amazon / athena odbc driver cpe:2.3:a:amazon:athena_odbc_driver:*:*:*:*:*:*:*:*

References