CVE-2026-94384 - Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService
Imported from official source
Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/22/2026 10:00 AM PDT Description: Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLambda) is a Serverless Application Repository application that provides Lambda functions for integrating Amazon Connect with Salesforce. We identified CVE-2026-94384, a missing authorization issue in the sfExecuteAWSService Lambda function, which is used only during initial setup. The function dispatches caller-supplied parameters to privileged AWS service APIs without validating the caller's authorization. As a result, an IAM principal with lambda:InvokeFunction permission on the function can perform AWS operations that their own IAM permissions would otherwise deny. Impacted versions: >= 5.15 AND <= 5.24.16 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
This version
- Version
- 1 of 1
- Recorded
- September 22, 2026 17:30
- Change
- Initial
- Content hash
1c1fd5cc69c82f0557af47995e3a229b- All versions
- Revision history