SEPTEMBER 17, 2026
Live Feed
Back to database
Case File

CVE-2026-77810

CRITICAL · CVSS 9.9 EPSS 0.35% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-21 · Last synced 2026-09-17

CyberRota Analysis

AI-Generated

The Neptune connector is vulnerable, allowing users with access through Athena Federated Query to exploit properties in the associated Lambda function, potentially leading to unauthorized data exposure. This critical vulnerability (CVSS 9.9) necessitates immediate attention from organizations utilizing AWS Athena and Neptune services to safeguard their data integrity. Users should upgrade to aws-athena-query-federation version 2026.30.1 or later to mitigate this risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-77810
Severity
CRITICAL
CVSS
9.9
EPSS
0.35%

Original NVD Description

In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.