2026-133-AWSHigh
CVE-2026-108096: Improper authorization in query resolvers for SQL-backed models in AWS Amplify API Category
🔗 CVE IDs covered (1)
📋 Description
Bulletin ID: 2026-133-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 10/09/2026 11:00 AM PDT Description: AWS Amplify API Category is a CDK Construct library for defining GraphQL data models with authorization rules as AWS AppSync APIs. We identified CVE-2026-108096, where improper authorization in the query resolvers generated by @aws-amplify/graphql-index-transformer might allow an authenticated remote user to read records owned by other users of the same application via crafted queries. Impacted versions:
- @aws-amplify/graphql-index-transformer >=2.2.0,
- @aws-amplify/graphql-api-construct >=1.4.0,
- @aws-amplify/data-construct Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.