CVE-2026-75910
Last modified
CVE-2026-75910 is a medium-severity vulnerability rated 6.5/10 on the CVSS scale. Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at a database endpoint under the user's control, causing the connector to transmit the secret to that endpoint. To remediate this issue, users should upgrade to aws-athena-query-federation connectors version v2026.17.1 or later and ensure that any forked or derivative code is patched to incorporate the new fixes. EPSS estimates a 0.37% chance of exploitation in the next 30 days.
Description
Incorrect privilege assignment in the ClickHouse connector deployment template in Amazon Athena Federated Query prior to v2026.17.1 could allow an authenticated remote user to read arbitrary AWS Secrets Manager secrets in the deploying account by pointing the connector's connection string at an unrelated secret and at a database endpoint under the user's control, causing the connector to transmit the secret to that endpoint. To remediate this issue, users should upgrade to aws-athena-query-federation connectors version v2026.17.1 or later and ensure that any forked or derivative code is patched to incorporate the new fixes. Alternatively, to remediate this issue, users should redeploy the connector with the current template and supply a non-empty SecretNamePrefix value.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| AWS | Athena Federated Query Clickhouse Connector deployment template | < 2026.17.1 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-75910?
How severe is CVE-2026-75910?
How do I fix CVE-2026-75910?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-7590A vulnerability was identified in eyal-gor p_69_branch_monke…7.3
- CVE-2026-75900An out-of-bounds read vulnerability was found in swtpm's SWT…6.1
- CVE-2026-75904libmodplug through 0.8.9.1 contains an out-of-bounds read in…3.3
- CVE-2026-75905The WP Recipe Maker plugin for WordPress is vulnerable to au…4.3
- CVE-2026-75908The Newsletters plugin for WordPress is vulnerable to author…4.3
- CVE-2026-7591A security flaw has been discovered in TimBroddin astro-mcp-…6.3
- CVE-2026-75911CodeWhale versions before 0.8.64 fail to properly validate t…7.8
- CVE-2026-75912CodeWhale versions before 0.8.64 contain an argument injecti…7.4
- CVE-2026-75913CodeWhale (codewhale / codewhale-tui) versions >= 0.8.41 and…9.3
- CVE-2026-75914CodeWhale versions before 0.8.64 contain a path traversal vu…7.5
- CVE-2026-75915CodeWhale versions before 0.8.64 contain an environment vari…7.5
- CVE-2026-75916SiYuan through 3.7.3 contains a cross-site scripting vulnera…8.6
Are you affected by CVE-2026-75910?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
