OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-94384

HIGH · CVSS 8.1 EPSS 0.32% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-09-22 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability allows any IAM principal with the lambda:InvokeFunction permission to escalate privileges and perform unauthorized AWS API operations by invoking a Lambda function that lacks proper authorization checks. This can lead to significant security risks, as it enables users to bypass IAM restrictions and access sensitive resources. Organizations utilizing Amazon Connect Salesforce Lambda prior to version 5.26 should prioritize remediation to mitigate potential exploitation.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-94384
Severity
HIGH
CVSS
8.1
EPSS
0.32%

Original NVD Description

Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API operations that their own IAM identity is explicitly denied, via invocation of a Lambda function that dispatches caller-supplied parameters to privileged service APIs without authorization validation. To remediate this issue, we recommend upgrading to version 5.26 or later. After setup is complete, either delete or disable the sfExecuteAWSService function. If you retain the function, restrict invocation to the intended IAM user only.