PT-2026-39186 · Amazon · Amazon Redshift Jdbc Driver

·

CVE-2026-8178

·

Published

2026-05-08

·

Updated

2026-06-19

CVSS v4.0

9.2

Critical

VectorAV:N/AC:H/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Amazon Redshift JDBC Driver versions prior to 2.2.2
Description An issue allows the driver to load and execute arbitrary classes when processing JDBC connection URL parameters. An actor capable of influencing the connection URL could potentially execute code within the application context, provided a suitable class exists on the application's classpath.
Recommendations Upgrade to version 2.2.2 or later.

Exploit

Fix

RCE

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-8178
GHSA-WMMV-VVG5-993Q

Affected Products

Amazon Redshift Jdbc Driver