AUGUST 4, 2026
Live Feed
Back to database
Case File

CVE-2026-35560

HIGH · CVSS 7.4 EPSS 0.26%

Source: NVD + CISA KEV + EPSS (historical backfill) · Published 2026-04-03 · Last synced 2026-08-04

CyberRota Analysis

This is a high severity vulnerability with a CVSS score of 7.4. See the original NVD description below for full technical details.

CVE
CVE-2026-35560
Severity
HIGH
CVSS
7.4
EPSS
0.26%

Original NVD Description

Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to connections with external identity providers and does not apply to connections with Athena. To remediate this issue, users should upgrade to version 2.1.0.0.

Related CVEs

Other vulnerabilities affecting the same vendor(s)