CVE-2026-75910 - Issue with Athena Federated Query Clickhouse Connector
Amazon Athena ยท 2026-09-09
Actions
Technical Details
| Affected Versions | < V2026.17.1 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-75910 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update the Athena Federated Query Clickhouse Connector to version V2026.17.1 to address the security vulnerability (CVE-2026-75910) and ensure that any forked or derivative code is patched accordingly.
For Platform Teams
Deploy the updated Athena Federated Query Clickhouse Connector template with a non-empty SecretNamePrefix value to mitigate the security risk and maintain the integrity of AWS Secrets Manager secrets.
For Executives
Implement the security patch for Athena Federated Query Clickhouse Connector to prevent unauthorized access to AWS Secrets Manager secrets, thereby mitigating potential security risks and ensuring data integrity.
Source
Related Amazon Athena Updates
- CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector (2026-09-09)
- CVE-2026-77810 - Issue with Athena Federated Query Neptune Connector (2026-08-21)
- CVE-2026-12283 - Issue with Athena Federated Query Synapse Connector (2026-08-20)
- CVE-2026-75910 - Issue with Athena Federated Query Clickhouse Connector (2026-08-20)
- Issues with Amazon Athena ODBC Driver (2026-08-20)