CVE detail
CVE-2026-35558
Improper neutralization of special elements in the authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to execute arbitrary code or redirect authentication flows by using specially crafted connection parameters that are processed by the driver during user-initiated authentication. To remediate this issue, users should upgrade to version 2.1.0.0.
Buzz score
Why this CVE is surfacing
This all-time snapshot uses the same composite formula as Trending across a 30-year evidence window, rather than a current rolling window.
Buzz score components · mention 19.5 · diversity 15.0 · KEV 0.0 · OTX 0.0 · PoC 0.0
Why it matters now
Mention timeline
- Total mentions
- 0
- within the 30d window
- Peak daily
- 0
- highest bucket
Evidence
Source links by recency
6 source links · newest first
- https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Windows/AmazonAthenaODBC-2.1.0.0.msidownloads.athena.us-east-1.amazonaws.com
No excerpt available.
Patchdownloads.athena.us-east-1.amazonaws.comApr 3, 2026, 9:17 PM - https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/arm/AmazonAthenaODBC-2.1.0.0_arm.pkgdownloads.athena.us-east-1.amazonaws.com
No excerpt available.
Patchdownloads.athena.us-east-1.amazonaws.comApr 3, 2026, 9:17 PM - https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/Intel/AmazonAthenaODBC-2.1.0.0_x86.pkgdownloads.athena.us-east-1.amazonaws.com
No excerpt available.
Patchdownloads.athena.us-east-1.amazonaws.comApr 3, 2026, 9:17 PM - https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Linux/AmazonAthenaODBC-2.1.0.0.rpmdownloads.athena.us-east-1.amazonaws.com
No excerpt available.
Patchdownloads.athena.us-east-1.amazonaws.comApr 3, 2026, 9:17 PM No excerpt available.
Release Notesdocs.aws.amazon.comApr 3, 2026, 9:17 PMNo excerpt available.
Vendor Advisoryaws.amazon.comApr 3, 2026, 9:17 PM
Exploit code
Public exploit repository references
Public PoC repositories are third-party, potentially unsafe artifacts. Treat their code as untrusted and use it only on authorized systems in an isolated, least-privilege environment. cvebuzz does not execute the code or verify that an exploit works.
0 repository references · best confidence N/A · max 0 stars
Related records
Similar CVEs
6 related CVEs with shared weakness or product evidence
- CVE-2026-35562CVSS 8.7 · High
Allocation of resources without limits in the parsing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to cause a denial of service by delivering…
- CVE-2026-35561CVSS 9.1 · Critical
Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or…
- CVE-2026-35560CVSS 9.1 · Critical
Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercep…
- CVE-2026-35559CVSS 7.1 · High
Out-of-bounds write in the query processing components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to crash the driver by using specially crafted data t…
- CVE-2024-41783CVSS 9.1 · Critical
IBM Sterling Secure Proxy 6.0.0.0, 6.0.0.1, 6.0.0.2, 6.0.0.3, 6.1.0.0, and 6.2.0.0 could allow a privileged user to inject commands into the underlying operating system due to imp…
- CVE-2022-40752CVSS 9.8 · Critical
IBM InfoSphere DataStage 11.7 is vulnerable to a command injection vulnerability due to improper neutralization of special elements. IBM X-Force ID: 236687.