2026-133-AWSHigh

CVE-2026-108096: Improper authorization in query resolvers for SQL-backed models in AWS Amplify API Category

Published
October 9, 2026
Last Modified
—

🔗 CVE IDs covered (1)

📋 Description

Bulletin ID: 2026-133-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/09/2026 11:00 AM PDT Description: AWS Amplify API Category is a CDK Construct library for defining GraphQL data models with authorization rules as AWS AppSync APIs. We identified CVE-2026-108096, where improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer might allow an authenticated remote user to read records owned by other users of the same application via crafted queries. Impacted versions:

  • @aws-amplify/graphql-index-transformer >=2.2.0,
  • @aws-amplify/graphql-api-construct >=1.4.0,
  • @aws-amplify/data-construct Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.

🔗 References (1)