PT-2026-67493 · Duckdb · Duckdb-Aws

·

CVE-2026-58139

·

Published

2026-08-03

·

Updated

2026-08-03

CVSS v3.1

6.5

Medium

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to extract plaintext AWS credentials by calling the load aws credentials function with the redact secret parameter set to false, circumventing the database-wide allow unredacted secrets=false policy. Attackers can invoke this single function to retrieve the underlying AWS credential chain including access key id, secret access key, session token, and region in plaintext, which are immediately valid against AWS APIs and particularly impactful in managed environments where pg duckdb is preloaded and an AWS credential chain such as IMDSv2, IRSA, ECS task role, or EC2 instance role is reachable.

Fix

Incorrect Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-58139

Affected Products

Duckdb-Aws