Shattered AWS Lambda IAM Bypass Flaw CVE-2026-94384 Gains Attention
Article Content
- •CVE-2026-94384 allows IAM principals to bypass permissions in AWS Lambda.
- •AWS patched the vulnerability in June 2026, but the advisory was delayed until September.
- •The flaw highlights significant visibility issues in AWS's Serverless Application Repository.
A privilege-escalation vulnerability, CVE-2026-94384, was discovered in AWS's Lambda function, sfExecuteAWSService, which allows IAM principals to bypass permissions and execute unauthorized AWS API operations. AWS patched the flaw in June 2026, but the advisory was only published on September 22, leading to increased attention in early October. The vulnerability affects users of the AmazonConnectSalesforceLambda integration, enabling attackers with minimal permissions to exploit the function's execution role. This incident highlights the lack of visibility in AWS's Serverless Application Repository and raises concerns about IAM misconfigurations across major cloud platforms. The CVSS score for this vulnerability is 8.1, indicating a high severity level. Security teams are urged to review their IAM policies and patch accordingly.
Ask AI about this cluster
Answers cite the sources they use
Timeline
More articles in this cluster (2)
Following this threat?
Track AWS and CVE-2026-12530 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.
Free account · no card needed
Common questions
What is CVE-2026-94384?
How can I mitigate this vulnerability?
When was this vulnerability patched?
Continue Reading
CVE-2015-3306 Exploited in ProFTPD FTP Servers CVE-2015-3306, a vulnerability in ProFTPD 1.3.5, allows remote attackers to read and write arbitrary files using the SITE CPFR and SITE CPTO commands. This exploit can lead to unauthorized access and potential remote code execution, as the commands are executed with the privileges of the ProFTPD service. Active…
CISA Mandates Urgent Patching of Five Critical Flaws Exploited by Flax Typhoon The U.S. Cybersecurity and Infrastructure Security Agency (CISA) has ordered federal agencies to patch five critical vulnerabilities by October 11, 2026, following exploitation by the China-linked hacking group Flax Typhoon. The vulnerabilities, added to CISA's Known Exploited Vulnerabilities (KEV) catalog, include…