CVE-2026-75910 - Issue with Athena Federated Query Clickhouse Connector

Imported from official source

Security notice

Cybersecurity Classified by Officially

CVE-2026-75910 - Issue with Athena Federated Query Clickhouse Connector

Bulletin ID: 2026-084-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 08/20/2026 13:00 PM PDT

Amazon Athena is a serverless, interactive query service that lets you analyze data directly in Amazon S3 using standard SQL. Athena Query Federation is a feature that allows you to connect to data sources outside of Amazon S3 like DynamoDB, Azure Synapse, and custom connectors using standard SQL syntax. These connectors are open source and deployed to the Athena service on a regular basis. We identified CVE-2026-75910. Incorrect privilege assignment in the ClickHouse connector deployment template before the v2026.17.1 release could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at a database endpoint under the user's control, causing the connector to transmit the secret to that endpoint.

This issue has been addressed in aws-athena-query-federation version V2026.17.1. We recommend upgrading to the latest version and ensuring that any forked or derivative code is patched to incorporate the new fixes.

To work around the issue, users should redeploy the connector with the current template and supply a non-empty SecretNamePrefix value.

We would like to thank Changli from Xidian University for collaborating on this issue through the coordinated vulnerability disclosure process.
 

This is an extract. The publication continues at the source.

Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-084-aws/

Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Amazon Web Services — imported from official source
Official source
https://aws.amazon.com/security/security-bulletins/feed/ RSS
Imported
September 18, 2026 09:42
Versions
1 recorded
Identity
65152f6a010d39cb8e68f45bb0f14528eb4d7b62

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.