Answer in brief
CVE-2026-107352 records a Medium severity (CVSS 6.3) vulnerability in Missing authorization checks in Amazon Athena engine version 3 request handling. The current sources do not mark it as known exploited. The current feed maps AWS/Amazon Athena (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 6.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps AWS/Amazon Athena (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| AWS/Amazon Athenageneric | N/A | Not reported |
Published upstream
Oct 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Oct 7, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Oct 7, 2026
Missing authorization checks in Amazon Athena engine version 3 request handling could have allowed an authenticated user to read limited query metadata (AWS account identifiers and SQL statement text) from other AWS accounts. Query results, credentials, and Amazon S3 data were not affected. AWS remediated the issue on September 1, 2026, and has confirmed no customer metadata was accessed. No customer action is required.
Quoted source text, attributed separately from HOL analysis.