CVE-2026-94384

Source
https://cve.org/CVERecord?id=CVE-2026-94384
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94384.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-94384
Aliases
  • GHSA-c9j2-qjfv-mm4p
Published
2026-09-22T17:07:12Z
Modified
2026-09-23T03:47:37Z
Severity
  • 6.4 (Medium) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:L/VI:L/VA:N/SC:H/SI:H/SA:N CVSS Calculator
Summary
Missing Authorization in sfExecuteAWSService Lambda Dispatcher in Amazon Connect Salesforce Lambda
Details

Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API operations that their own IAM identity is explicitly denied, via invocation of a Lambda function that dispatches caller-supplied parameters to privileged service APIs without authorization validation.

To remediate this issue, we recommend upgrading to version 5.26 or later. After setup is complete, either delete or disable the sfExecuteAWSService function. If you retain the function, restrict invocation to the intended IAM user only.

Database specific
{
    "cna_assigner":  "AMZN",
    "cwe_ids":  [
        "CWE-862"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/94xxx/CVE-2026-94384.json",
    "unresolved_ranges":  [
        {
            "extracted_events":  [
                {
                    "introduced":  "5.15"
                },
                {
                    "last_affected":  "5.24.16"
                }
            ],
            "source":  "AFFECTED_FIELD"
        },
        {
            "extracted_events":  [
                {
                    "introduced":  "5.15"
                },
                {
                    "last_affected":  "5.24.16"
                }
            ],
            "source":  "CPE_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/amazon-connect/amazon-connect-salesforce-lambda

Affected ranges

Type
GIT
Repo
https://github.com/amazon-connect/amazon-connect-salesforce-lambda
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "5.26"
        }
    ],
    "source":  "DESCRIPTION"
}

Affected versions

v5.*
v5.0
v5.16
v5.19.7
v5.22
v5.23
v5.7
v5.9

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-94384.json"