PT-2026-30219 · Amazon · Amazon Athena Odbc Driver+1

Published

2026-04-03

·

Updated

2026-04-03

·

CVE-2026-35560

CVSS v3.1

7.4

High

VectorAV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to connections with external identity providers and does not apply to connections with Athena.
To remediate this issue, users should upgrade to version 2.1.0.0.

Fix

Improper Certificate Validation

Weakness Enumeration

Related Identifiers

CVE-2026-35560

Affected Products

Amazon Athena Odbc Driver
Athena Odbc