CVE-2026-5485
CVE-2026-5485
7.3
HighPublished:
Last updated:
Source:ff89ba41-3aa1-4d27-914a-91399e9639e5
Analyzed
Weakness (CWE)
CVSS Vector
v4.0- Attack Vector
- Local
- Attack Complexity
- Low
- Attack Requirements
- Present
- Privileges Required
- None
- User Interaction
- Passive
- Confidentiality (Vulnerable)
- High
- Integrity (Vulnerable)
- High
- Availability (Vulnerable)
- High
- Confidentiality (Subsequent)
- None
- Integrity (Subsequent)
- None
- Availability (Subsequent)
- None
Description
OS command injection in the browser-based authentication component in Amazon Athena ODBC driver before 2.0.5.1 on Linux might allow a threat actor to execute arbitrary code by using specially crafted connection parameters that are loaded by the driver during a local user-initiated connection. To remediate this issue, users should upgrade to version 2.0.5.1 or later.
References
ff89ba41-3aa1-4d27-914a-91399e9639e5
https://aws.amazon.com/security/security-bulletins/2026-013-aws/ff89ba41-3aa1-4d27-914a-91399e9639e5
https://docs.aws.amazon.com/athena/latest/ug/odbc-v2-driver-release-notes.htmlff89ba41-3aa1-4d27-914a-91399e9639e5
https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Linux/AmazonAthenaODBC-2.1.0.0.rpmff89ba41-3aa1-4d27-914a-91399e9639e5
https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/Intel/AmazonAthenaODBC-2.1.0.0_x86.pkgff89ba41-3aa1-4d27-914a-91399e9639e5
https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/arm/AmazonAthenaODBC-2.1.0.0_arm.pkgff89ba41-3aa1-4d27-914a-91399e9639e5
https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Windows/AmazonAthenaODBC-2.1.0.0.msi