CVE-2026-77810 CRITICAL

CVE-2026-77810: Code Injection via Gremlin Query Passthrough in Amazon Athena Neptune Connector

Vendor Aws
Product Athena Federated Query Neptune Connector
Weakness CWE-95 · Eval injection
Published August 21, 2026
Last update August 27, 2026

CVSS base score

9.9/10
Attack vector Network
Attack complexity Low
Privileges required Low
User interaction None
Confidentiality High
Integrity High

CVSS vector

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H

What the vulnerability does

01Description

In the Neptune connector, a user with access to Neptune through Athena Federated Query could gain access to properties in the Lambda supplying the compute for the connector. To remediate this issue, users should upgrade to aws-athena-query-federation v2026.30.1 or later.

Key dates

02Disclosure timeline

August 21, 2026 CVE published
August 27, 2026 Record updated

Related vulnerabilities

04Related CVE