---
id: CVE-2026-107352
title: >-
  Missing authorization checks in Amazon Athena engine version 3 request
  handling could have allowed an authenticated user to read limited query
  metadata (AWS account identifiers and SQL statement text) from other AWS
  accounts
summary: >-
  Missing authorization checks in Amazon Athena engine version 3 request
  handling could have allowed an authenticated user to read limited query
  metadata (AWS account identifiers and SQL statement text) from other AWS
  accounts. Query resul…
severity: high
cvss: 7.7
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N'
cwe:
  - CWE-424
  - CWE-862
vendor: AWS
product: Amazon Athena
affected:
  - amazon_athena N/A
published: '2026-10-07'
updated: '2026-10-07'
sourceUpdated: '2026-10-07T21:17:15.373'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-107352'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/2026-128-aws/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: partial
  timestamp: '2026-10-07T20:31:50.642279Z'
ingestedAt: '2026-10-07T20:46:46.989Z'
---

## Overview

Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, credentials, and Amazon S3 data were not affected. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. No customer action is required.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
