CVE-2026-94384 - Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService

Imported from official source

Security notice

Cybersecurity Classified by Officially

CVE-2026-94384 - Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService

Bulletin ID: 2026-115-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/22/2026 10:00 AM PDT

Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLambda) is a Serverless Application Repository application that provides Lambda functions for integrating Amazon Connect with Salesforce. We identified CVE-2026-94384, a missing authorization issue in the sfExecuteAWSService Lambda function, which is used only during initial setup. The function dispatches caller-supplied parameters to privileged AWS service APIs without validating the caller's authorization. As a result, an IAM principal with lambda:InvokeFunction permission on the function can perform AWS operations that their own IAM permissions would otherwise deny.

Impacted versions: >= 5.15 AND <= 5.24.16

To remediate this issue, upgrade to AmazonConnectSalesforceLambda version 5.26 or later. After setup is complete, either delete or disable the sfExecuteAWSService function. If you keep the function, restrict who can invoke it: within your account, grant lambda:InvokeFunction on the function only to the single IAM user the CTI Adapter uses to call it and to no other principal (for stronger enforcement, deny it for all other principals using a service control policy or permission boundary); and set the SalesforceExecuteAWSServiceUser parameter to that same IAM user so that cross-account invocation is limited to it.

Confirm the sfExecuteAWSService function has been deleted or disabled after setup. If you keep the function, confirm that within your account lambda:InvokeFunction on the function is granted only to the CTI Adapter's IAM user, and that the SalesforceExecuteAWSServiceUser parameter names that same user.

We would like to thank Chang Li of Xidian University for collaborating on this issue through the coordinated vulnerability disclosure process.

This is an extract. The publication continues at the source.

Read the original at the source: https://aws.amazon.com/security/security-bulletins/rss/2026-115-aws/

Officially imported this from Amazon Web Services’s own source and shows an extract. If you work there, claiming the profile and verifying the domain lets you choose to show the full text here.

Provenance

Organization
Amazon Web Services — imported from official source
Official source
https://aws.amazon.com/security/security-bulletins/feed/ RSS
Imported
September 22, 2026 17:30
Versions
1 recorded
Identity
3b1589f49bff05dc831457d3c9472c5588b9cc55

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.