CVE-2026-35560

Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to connections with external identity providers and does not apply to connections with Athena. To remediate this issue, users should upgrade to version 2.1.0.0.
Configurations

Configuration 1 (hide)

AND
cpe:2.3:a:amazon:athena_odbc:*:*:*:*:*:*:*:*
OR cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*

History

24 Jul 2026, 21:10

Type Values Removed Values Added
Summary
  • (es) La validación de certificado indebida en los componentes de conexión del proveedor de identidad en el controlador ODBC de Amazon Athena anterior a la versión 2.1.0.0 podría permitir que un actor de amenaza man-in-the-middle intercepte las credenciales de autenticación debido a una seguridad de transporte predeterminada insuficiente al conectarse a proveedores de identidad. Esto solo se aplica a conexiones con proveedores de identidad externos y no se aplica a conexiones con Athena. Para remediar este problema, los usuarios deberían actualizar a la versión 2.1.0.0.

14 Apr 2026, 16:14

Type Values Removed Values Added
CPE cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:*
cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:*
cpe:2.3:a:amazon:athena_odbc:*:*:*:*:*:*:*:*
cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:*
First Time Microsoft
Linux linux Kernel
Amazon
Linux
Microsoft windows
Apple macos
Apple
Amazon athena Odbc
References () https://aws.amazon.com/security/security-bulletins/2026-013-aws/ - () https://aws.amazon.com/security/security-bulletins/2026-013-aws/ - Vendor Advisory
References () https://docs.aws.amazon.com/athena/latest/ug/odbc-v2-driver-release-notes.html - () https://docs.aws.amazon.com/athena/latest/ug/odbc-v2-driver-release-notes.html - Release Notes
References () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Linux/AmazonAthenaODBC-2.1.0.0.rpm - () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Linux/AmazonAthenaODBC-2.1.0.0.rpm - Patch, Product
References () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/Intel/AmazonAthenaODBC-2.1.0.0_x86.pkg - () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/Intel/AmazonAthenaODBC-2.1.0.0_x86.pkg - Patch, Product
References () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/arm/AmazonAthenaODBC-2.1.0.0_arm.pkg - () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/arm/AmazonAthenaODBC-2.1.0.0_arm.pkg - Patch, Product
References () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Windows/AmazonAthenaODBC-2.1.0.0.msi - () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Windows/AmazonAthenaODBC-2.1.0.0.msi - Patch, Product

03 Apr 2026, 21:17

Type Values Removed Values Added
New CVE

Information

Published : 2026-04-03 21:17

Updated : 2026-07-24 21:10


NVD link : CVE-2026-35560

Mitre link : CVE-2026-35560

CVE.ORG link : CVE-2026-35560


JSON object : View

Products Affected

amazon

  • athena_odbc

microsoft

  • windows

apple

  • macos

linux

  • linux_kernel
CWE
CWE-295

Improper Certificate Validation