---
id: CVE-2026-94384
title: >-
  Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26
  allows any IAM principal with lambda:InvokeFunction permission on the affected
  function to escalate privileges and perform AWS API operations that their own
  IAM…
summary: >-
  Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26
  allows any IAM principal with lambda:InvokeFunction permission on the affected
  function to escalate privileges and perform AWS API operations that their own
  IAM…
severity: high
cvss: 8.1
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N'
cwe:
  - CWE-862
vendor: Amazon
product: amazon-connect-salesforce-lambda
affected:
  - amazon-connect-salesforce-lambda >= 5.15 <= 5.24.16
published: '2026-09-22'
updated: '2026-09-22'
sourceUpdated: '2026-09-22T19:16:59.070'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-94384'
references:
  - url: 'https://aws.amazon.com/security/security-bulletins/2026-115-aws/'
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: >-
      https://github.com/amazon-connect/amazon-connect-salesforce-cti/security/advisories/GHSA-c9j2-qjfv-mm4p
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
  - url: >-
      https://github.com/amazon-connect/amazon-connect-salesforce-lambda/releases/tag/v5.26
    label: ff89ba41-3aa1-4d27-914a-91399e9639e5
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'no'
  technicalImpact: total
  timestamp: '2026-09-22T18:23:33.149321Z'
ingestedAt: '2026-09-22T18:08:12.503Z'
epss: 0.00252
epssPercentile: 0.14808
---

## Overview

Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API operations that their own IAM identity is explicitly denied, via invocation of a Lambda function that dispatches caller-supplied parameters to privileged service APIs without authorization validation.



To remediate this issue, we recommend upgrading to version 5.26 or later. After setup is complete, either delete or disable the sfExecuteAWSService function. If you retain the function, restrict invocation to the intended IAM user only.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
