CVE-2026-11400High· 8.0▾ TwilightAWS-JDBC Wrapper: Privilege Escalation in Aurora PostgreSQL instance
▾ Twilight zone — High severity, or a signal on a lesser flaw
impact 44 · likelihood 0.1 · exploitation 0
Need a working PoC? Pro members can cast a request and our team develops one — it lands right here.
Exploit-prediction probability, daily snapshots since Jul 17.
Disclosure to exploitation, from the record and what we observed since indexing it.
Disclosed via GHSA
0.3%
Aurora PostgreSQL is a fully managed relational database engine that's compatible with PostgreSQL.
The team has identified CVE-2026-11400, an issue in Aurora PostgreSQL using the AWS Advanced JDBC Wrapper
Impact An issue in AWS Wrappers for Amazon Aurora PostgreSQL will allow for privilege escalation to rds_superuser role. A low privilege authenticated user can create a crafted function that could be executed with permissions of other Amazon Relational Database Service (RDS) users.
Impacted versions: AWS Advanced JDBC Wrapper >= 3.0.0 and < 4.0.1
Patches This issue has been addressed in AWS JDBC Wrapper v4.0.1. It is recommended to upgrade to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds Remove the public schema from the search path.
Resources If there are any questions or comments about this advisory, contact [AWS/Amazon] Security via vulnerability reporting page or directly via email to [email protected]. Please do not create a public GitHub issue.
Acknowledgement
AWS-JDBC Wrapper would like to thank x.com/ph0smet for collaborating on this issue through the coordinated vulnerability disclosure process.
software.amazon.jdbc:aws-advanced-jdbc-wrapper >= 3.0.0, < 4.0.1Upgrade to a patched release:
software.amazon.jdbc:aws-advanced-jdbc-wrapper 4.0.1Connected by shared product, vendor, weakness, or advisory.
CVE-2026-11401High· 8.0AWS Advanced Go Wrapper has Privilege Escalation in Aurora PostgreSQL instance
CVE-2026-94384High· 8.1Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API operations that their own IAM…
CVE-2023-32803High· 7.5The ca-certificates package before ca-certificates-2021.2.50-72 for Amazon Linux 2 (AL2) does not properly remove certain TrustCor root certificates from the root store
CVE-2026-18061Medium· 5.9Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infrastructure to disclose sensitive files f…
CVE-2026-89332Medium· 5.5Inclusion of functionality from an untrusted control sphere in the Kiro Powers feature in Amazon Kiro IDE before version 0.8.135 might allow remote unauthenticated actors to obtain sensitive information from a developer workstation
CVE-2026-85228Critical· 9.1Integer overflow in tensor buffer validation in Deep Java Library