CVE-2026-35560
Improper certificate validation in identity provider connection components in Amazon Athena ODBC driver
CVSS Score
7.4
EPSS Score
0.0%
EPSS Percentile
8th
Improper certificate validation in the identity provider connection components in Amazon Athena ODBC driver before 2.1.0.0 might allow a man-in-the-middle threat actor to intercept authentication credentials due to insufficient default transport security when connecting to identity providers. This only applies to connections with external identity providers and does not apply to connections with Athena. To remediate this issue, users should upgrade to version 2.1.0.0.
| CWE | CWE-295 |
| Vendor | amazon |
| Product | amazon athena odbc driver |
| Published | Apr 3, 2026 |
| Last Updated | Apr 7, 2026 |
Stay Ahead of the Next One
Get instant alerts for amazon amazon athena odbc driver
Be the first to know when new high vulnerabilities affecting amazon amazon athena odbc driver are published โ delivered to Slack, Telegram or Discord.
Get Free Alerts โ
Free ยท No credit card ยท 60 sec setup
CVSS v3 Breakdown
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N Attack Vector
Network
Attack Complexity
High
Privileges Required
None
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None
Affected Versions
Amazon / Amazon Athena ODBC driver
All versions affected References
downloads.athena.us-east-1.amazonaws.com: https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Windows/AmazonAthenaODBC-2.1.0.0.msi downloads.athena.us-east-1.amazonaws.com: https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Linux/AmazonAthenaODBC-2.1.0.0.rpm downloads.athena.us-east-1.amazonaws.com: https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/arm/AmazonAthenaODBC-2.1.0.0_arm.pkg downloads.athena.us-east-1.amazonaws.com: https://downloads.athena.us-east-1.amazonaws.com/drivers/ODBC/v2.1.0.0/Mac/Intel/AmazonAthenaODBC-2.1.0.0_x86.pkg aws.amazon.com: https://aws.amazon.com/security/security-bulletins/2026-013-aws/ docs.aws.amazon.com: https://docs.aws.amazon.com/athena/latest/ug/odbc-v2-driver-release-notes.html