SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-65321

CRITICAL · CVSS 9.8 EPSS 0.98% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-02 · Last synced 2026-09-01

CyberRota Analysis

AI-Generated

PyAthena versions prior to 3.35.4 are vulnerable to a SQL injection flaw that allows unauthenticated attackers to execute arbitrary SQL commands due to improper quote-escaping in the DefaultParameterFormatter.format() function. This vulnerability can lead to severe consequences, including data exfiltration and execution of destructive SQL statements. Organizations using PyAthena should prioritize patching to mitigate the risk of exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-65321
Severity
CRITICAL
CVSS
9.8
EPSS
0.98%

Original NVD Description

PyAthena prior to 3.35.4 contains a sql injection vulnerability that allows unauthenticated attackers to inject arbitrary SQL by exploiting improper quote-escaping in DefaultParameterFormatter.format(), which routes DELETE and CTAS statements to the _escape_hive function that backslash-escapes single quotes rather than doubling them. Because Athena and Trino do not treat backslashes as escape characters inside string literals, attacker-supplied input such as a single quote followed by SQL syntax causes the parser to terminate the string literal prematurely, enabling data exfiltration via UNION SELECT, execution of destructive statements, and attacker-controlled CTAS destination and content.