CVE-2026-35560 details an improper certificate validation vulnerability in Amazon Athena ODBC driver versions prior to 2.1.0.0, affecting connections to external identity providers. This high-severity flaw (CVSS 7.4) could enable a man-in-the-middle attacker to intercept authentication credentials due to insufficient default transport security, though it requires high attack complexity. The potential impact is high for confidentiality and integrity. There is currently no evidence of active exploitation, no public exploit code available, and minimal community discussion surrounding this vulnerability. Users should upgrade to version 2.1.0.0 to remediate this issue.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
< 2.1.0.0CPE matchmatch criteria | cpe:2.3:a:amazon:athena_odbc:*:*:*:*:*:*:*:* |
CVSS version used by this source: 4.0
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.