Skip to content
AWS Lambda IAM Bypass Flaw CVE-2026-94384 Gains Attention

AWS Lambda IAM Bypass Flaw CVE-2026-94384 Gains Attention

First seen 11 Oct 2026, 09:31 UTC • •

Article Content

Browse articles
ThreatCluster AI
ThreatCluster •October 11, 2026 at 17:31 UTC

A privilege-escalation vulnerability, CVE-2026-94384, was discovered in AWS's Lambda function, sfExecuteAWSService, which allows IAM principals to bypass permissions and execute unauthorized AWS API operations. AWS patched the flaw in June 2026, but the advisory was only published on September 22, leading to increased attention in early October. The vulnerability affects users of the AmazonConnectSalesforceLambda integration, enabling attackers with minimal permissions to exploit the function's execution role. This incident highlights the lack of visibility in AWS's Serverless Application Repository and raises concerns about IAM misconfigurations across major cloud platforms. The CVSS score for this vulnerability is 8.1, indicating a high severity level. Security teams are urged to review their IAM policies and patch accordingly.

Start a free Starter trial for enhanced analysis

Ask AI about this cluster

Updated just now How this analysis works

Timeline

2026-06-17
CVE-2026-12530 published
AWS disclosed a critical vulnerability in the Amazon Bedrock AgentCore SDK affecting AWS credentials.
Msspalert
2026-07-23
CVE-2026-16796 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-08-26
CVE-2026-80521 published
Vulnerability assigned a CVE identifier and published in the National Vulnerability Database.
MITRE
2026-09-22
CVE-2026-94384 advisory published
AWS published an advisory for the IAM bypass vulnerability in Lambda, tracked as CVE-2026-94384.
Shattered
2026-10-09
Media coverage increases
Security trackers and trade press began reporting on the AWS Lambda IAM bypass flaw, raising awareness.
Shattered
2026-10-10
Continued media attention
The AWS Lambda vulnerability continued to gain traction in cloud security discussions worldwide.
Shattered

More articles in this cluster (2)

Following this threat?

Track AWS and CVE-2026-12530 in your own feed — you're alerted when they show up in new reporting, leak sites or exploitation.

Free account · no card needed

Common questions

What is CVE-2026-94384?
CVE-2026-94384 is a privilege-escalation vulnerability in AWS Lambda that allows IAM principals to bypass permissions.
How can I mitigate this vulnerability?
Review your IAM policies and ensure that only necessary permissions are granted to Lambda functions.
When was this vulnerability patched?
AWS patched the vulnerability in June 2026, but the advisory was published on September 22, 2026.