EXPOSURES › CVE-2026-35561
CVE-2026-35561
HIGH
DETAIL
SourceNVD · cve
Published2026-04-03
CVSS7.4
Referencehttps://nvd.nist.gov/vuln/detail/CVE-2026-35561 ↗
▸ RECOMMENDED ACTION Patch the affected products and confirm your instances are covered.
PLAYERS IMPLICATED
DESCRIPTION
Insufficient authentication security controls in the browser-based authentication components in Amazon Athena ODBC driver before 2.1.0.0 might allow a threat actor to intercept or hijack authentication sessions due to insufficient protections in the browser-based authentication flows. To remediate this issue, users should upgrade to version 2.1.0.0.
AFFECTED FEDRAMP PRODUCTS · 6
| PRODUCT | STATUS |
|---|---|
| AWS GovCloud Amazon |
Authorized |
| AWS US East/West Amazon |
Authorized |
| Azure Commercial Cloud Microsoft |
Authorized |
| Azure Government (includes Dynamics 365) Microsoft |
Authorized |
| Microsoft Office 365 GCC High Microsoft |
In Process |
| Office 365 Multi-Tenant & Supporting Services Microsoft |
Authorized |