Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to connections with external identity providers and does not apply to connections with Athena.
To remediate this issue, users should upgrade to version 2.1.0.0.
References
Configurations
Configuration 1 (hide)
| AND |
|
History
14 Apr 2026, 16:14
| Type | Values Removed | Values Added |
|---|---|---|
| First Time |
Microsoft
Linux linux Kernel Amazon Linux Microsoft windows Apple macos Apple Amazon athena Odbc |
|
| References | () https://aws.amazon.com/security/security-bulletins/2026-013-aws/ - Vendor Advisory | |
| References | () https://docs.aws.amazon.com/athena/latest/ug/odbc-v2-driver-release-notes.html - Release Notes | |
| References | () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Linux/AmazonAthenaODBC-2.1.0.0.rpm - Patch, Product | |
| References | () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/Intel/AmazonAthenaODBC-2.1.0.0_x86.pkg - Patch, Product | |
| References | () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/arm/AmazonAthenaODBC-2.1.0.0_arm.pkg - Patch, Product | |
| References | () https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Windows/AmazonAthenaODBC-2.1.0.0.msi - Patch, Product | |
| CPE | cpe:2.3:o:microsoft:windows:-:*:*:*:*:*:*:* cpe:2.3:o:apple:macos:-:*:*:*:*:*:*:* cpe:2.3:a:amazon:athena_odbc:*:*:*:*:*:*:*:* cpe:2.3:o:linux:linux_kernel:-:*:*:*:*:*:*:* |
03 Apr 2026, 21:17
| Type | Values Removed | Values Added |
|---|---|---|
| New CVE |
Information
Published : 2026-04-03 21:17
Updated : 2026-04-14 16:14
NVD link : CVE-2026-35560
Mitre link : CVE-2026-35560
CVE.ORG link : CVE-2026-35560
JSON object : View
Products Affected
amazon
- athena_odbc
microsoft
- windows
apple
- macos
linux
- linux_kernel
CWE
CWE-295
Improper Certificate Validation
