CVE-2026-105811

Source
https://cve.org/CVERecord?id=CVE-2026-105811
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105811.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-105811
Published
2026-10-06T20:03:31Z
Modified
2026-10-08T02:49:18Z
Severity
  • 7.1 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N CVSS Calculator
Summary
Authorization bypass through a user-controlled key in the Amazon Q Business Lambda hook sample in QnABot on AWS
Details

Authorization bypass through a user-controlled key in the optional Amazon Q Business Lambda hook sample ( q-business-lambda-hook https://github.com/aws-solutions-library-samples/qnabot-on-aws/blob/main/source/docs/lambda_hooks/README.md ), available with QnABot on AWS versions 7.0.0 through 7.4.5, might allow an authenticated remote user to read arbitrary Amazon S3 objects in the deploying AWS account. This sample solution provides an example Lambda hook and requires separate, manual deployment and additional setup. It is not deployed automatically with QnABot. Customers who have not deployed this optional sample hook are not affected and do not need to take action.

To remediate this issue, affected customers should update the QnABot on AWS stack to version 7.4.6 or later and then redeploy the Amazon Q Business Lambda hook sample stack. Updating the QnABot on AWS stack alone does not deliver the fix.

Database specific
{
    "cna_assigner": "AMZN",
    "cwe_ids": [
        "CWE-639"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/105xxx/CVE-2026-105811.json"
}
References

Affected packages

Git / github.com/aws-solutions-library-samples/qnabot-on-aws

Affected ranges

Type
GIT
Repo
https://github.com/aws-solutions-library-samples/qnabot-on-aws
Events
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "7.0.0"
        },
        {
            "fixed": "7.4.6"
        }
    ],
    "source": "AFFECTED_FIELD"
}

Affected versions

v7.*
v7.0.0
v7.0.1
v7.0.2
v7.0.3
v7.0.4
v7.0.5
v7.0.6
v7.0.7
v7.1.0
v7.1.1
v7.1.2
v7.1.3
v7.2.0
v7.2.1
v7.2.2
v7.2.3
v7.2.4
v7.3.0
v7.3.1
v7.3.10
v7.3.11
v7.3.12
v7.3.13
v7.3.14
v7.3.15
v7.3.16
v7.3.2
v7.3.3
v7.3.4
v7.3.5
v7.3.6
v7.3.7
v7.3.8
v7.3.9
v7.4.0
v7.4.1
v7.4.2
v7.4.3
v7.4.4
v7.4.5

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-105811.json"