---
id: CVE-2026-105811
title: >-
  Authorization bypass through a user-controlled key in the optional Amazon Q
  Business Lambda hook sample ( q-business-lambda-hook
  https://github.com/aws-solutions-library-samples/qnabot-on-aws/blob/main/source/docs/lambda_hooks/README.md
  …
summary: >-
  Authorization bypass through a user-controlled key in the optional Amazon Q
  Business Lambda hook sample ( q-business-lambda-hook
  https://github.com/aws-solutions-library-samples/qnabot-on-aws/blob/main/source/docs/lambda_hooks/README.md
  …
severity: medium
cvss: 6.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-639
vendor: aws
product: qnabot-on-aws
affected:
  - qnabot-on-aws >= 7.0.0 < 7.4.6
published: '2026-10-06'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T16:17:34.163'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-105811'
references:
  - url: >-
      https://github.com/aws-solutions-library-samples/qnabot-on-aws/releases/tag/v7.4.6
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: >-
      https://staging.prod.website.marketing.aws.dev/security/security-bulletins/2026-126-aws/
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T14:53:00.915761Z'
ingestedAt: '2026-10-06T21:20:28.978Z'
---

## Overview

Authorization bypass through a user-controlled key in the optional Amazon Q Business Lambda hook sample ( q-business-lambda-hook https://github.com/aws-solutions-library-samples/qnabot-on-aws/blob/main/source/docs/lambda_hooks/README.md ), available with QnABot on AWS versions 7.0.0 through 7.4.5, might allow an authenticated remote user to read arbitrary Amazon S3 objects in the deploying AWS account. This sample solution provides an example Lambda hook and requires separate, manual deployment and additional setup. It is not deployed automatically with QnABot. Customers who have not deployed this optional sample hook are not affected and do not need to take action. 



To remediate this issue, affected customers should update the QnABot on AWS stack to version 7.4.6 or later and then redeploy the Amazon Q Business Lambda hook sample stack. Updating the QnABot on AWS stack alone does not deliver the fix.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
