CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector

Imported from official source

Security notice

Cybersecurity Classified by Officially

CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector

Bulletin ID: 2026-087-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/21/2026 12:30 PM PDT

Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. These connectors are open source and deployed to the Athena service on a regular basis.

We identified CVE-2026-77810, in the Neptune connector where a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector.

Impacted versions: <=v2026.28.1 AND >=v2024.15.1

This issue has been addressed in Athena Federated Query version v2026.30.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Alternatively, customers can mitigate this issue by disabling query passthrough on the connector, restricting athena:StartQueryExecution on the Neptune catalog, or ensure the passthrough query only contains Gremlin, openCypher, or SPARQL.

This is an extract. The publication continues at the source.

Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-087-aws/

Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

This publication has changed since it was first published

2 versions recorded. The original is kept in full — nothing is overwritten.

  1. v2 imported change on current
  2. v1 as first published on

Provenance

Organization
Amazon Web Services — imported from official source
Official source
https://aws.amazon.com/security/security-bulletins/feed/ RSS
Imported
September 15, 2026 20:57
Versions
2 recorded
Identity
290980565a61de785256e60428408ebf995366bc

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.