CVE-2026-94384 - Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService

Amazon Web Services Version 1 original current

Imported from official source

Bulletin ID: 2026-115-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/22/2026 10:00 AM PDT Description: Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLambda) is a Serverless Application Repository application that provides Lambda functions for integrating Amazon Connect with Salesforce. We identified CVE-2026-94384, a missing authorization issue in the sfExecuteAWSService Lambda function, which is used only during initial setup. The function dispatches caller-supplied parameters to privileged AWS service APIs without validating the caller's authorization. As a result, an IAM principal with lambda:InvokeFunction permission on the function can perform AWS operations that their own IAM permissions would otherwise deny. Impacted versions: >= 5.15 AND <= 5.24.16 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

This version

Version
1 of 1
Recorded
September 22, 2026 17:30
Change
Initial
Content hash
1c1fd5cc69c82f0557af47995e3a229b
All versions
Revision history

Officially records where a publication came from, not whether it is true. Imported records are reproduced from an organization's own official source.