CVE-2026-94384

HIGH Status: Awaiting Analysis

CVSS Scores

CVSS v3.x Base Score
8.1
HIGH

Description

Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API operations that their own IAM identity is explicitly denied, via invocation of a Lambda function that dispatches caller-supplied parameters to privileged service APIs without authorization validation. To remediate this issue, we recommend upgrading to version 5.26 or later. After setup is complete, either delete or disable the sfExecuteAWSService function. If you retain the function, restrict invocation to the intended IAM user only.

Published
September 22, 2026 6:17 PM
Last Modified
September 22, 2026 7:16 PM
Source
ff89ba41-3aa1-4d27-914a-91399e9639e5

Weaknesses (CWE)

CWE-862

References

Contact Us

Get the CyboWatch SIEM platform, hosting, and 24×7 SOC analysts. Call or email us to get started.