๐Ÿ” CVE Alert

CVE-2026-105811

MEDIUM 6.5

Authorization bypass through a user-controlled key in the Amazon Q Business Lambda hook sample in QnABot on AWS

CVSS Score
6.5
EPSS Score
0.0%
EPSS Percentile
0th

Authorization bypass through a user-controlled key in the optional Amazon Q Business Lambda hook sample ( q-business-lambda-hook https://github.com/aws-solutions-library-samples/qnabot-on-aws/blob/main/source/docs/lambda_hooks/README.md ), available with QnABot on AWS versions 7.0.0 through 7.4.5, might allow an authenticated remote user to read arbitrary Amazon S3 objects in the deploying AWS account. This sample solution provides an example Lambda hook and requires separate, manual deployment and additional setup. It is not deployed automatically with QnABot. Customers who have not deployed this optional sample hook are not affected and do not need to take action. To remediate this issue, affected customers should update the QnABot on AWS stack to version 7.4.6 or later and then redeploy the Amazon Q Business Lambda hook sample stack. Updating the QnABot on AWS stack alone does not deliver the fix.

CWE CWE-639
Vendor aws
Product qnabot-on-aws
Published Oct 6, 2026
Stay Ahead of the Next One

Get instant alerts for aws qnabot-on-aws

Be the first to know when new medium vulnerabilities affecting aws qnabot-on-aws are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
None
Availability
None

Affected Versions

aws / qnabot-on-aws
7.0.0 < 7.4.6

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/aws-solutions-library-samples/qnabot-on-aws/releases/tag/v7.4.6 staging.prod.website.marketing.aws.dev: https://staging.prod.website.marketing.aws.dev/security/security-bulletins/2026-126-aws/