PT-2026-67493 · Duckdb · Duckdb-Aws

·

CVE-2026-58139

·

Publicado

2026-08-03

·

Atualizado

2026-08-03

CVSS v3.1

6.5

Média

VetorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to extract plaintext AWS credentials by calling the load aws credentials function with the redact secret parameter set to false, circumventing the database-wide allow unredacted secrets=false policy. Attackers can invoke this single function to retrieve the underlying AWS credential chain including access key id, secret access key, session token, and region in plaintext, which are immediately valid against AWS APIs and particularly impactful in managed environments where pg duckdb is preloaded and an AWS credential chain such as IMDSv2, IRSA, ECS task role, or EC2 instance role is reachable.

Correção

Incorrect Authorization

Encontrou algum problema na descrição? Tem algo a acrescentar? Fique à vontade para nos escrever 👾

Enumeração de Fraquezas

Identificadores relacionados

CVE-2026-58139

Produtos afetados

Duckdb-Aws