CVE-2026-35558 is a high-severity vulnerability (CVSS 7.8) impacting Amazon Athena ODBC driver versions prior to 2.1.0.0, caused by improper neutralization of special elements in its authentication components. This flaw could enable a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection parameters during user-initiated authentication, requiring local access. While not yet listed in CISA's KEV catalog and lacking public exploit code, it is on an internal "Hot List" and has garnered minimal community discussion. Organizations should prioritize upgrading their Amazon Athena ODBC driver to version 2.1.0.0 or later to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.0.0CPE matchmatch criteria | cpe:2.3:a:amazon:athena_odbc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.