CVE-2026-18061 - XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin
Advanced Jdbc ยท 2026-09-11
Actions
Technical Details
| Affected Versions | >= 3.3.0, <= 4.2.0 |
|---|---|
| Regions | all |
| CVE IDs | CVE-2026-18061 |
| Migration Required | Yes |
| Cost Impact | Neutral |
| IaC Impact | High |
What This Means
For DevOps Teams
Update the AWS Advanced JDBC Wrapper to version 4.3.0 to address the XXE vulnerability (CVE-2026-18061) and ensure the security of your applications connecting to Amazon Aurora, RDS MySQL, and RDS MariaDB.
For Platform Teams
Integrate the latest version of AWS Advanced JDBC Wrapper (4.3.0) into your platform to resolve the XXE vulnerability (CVE-2026-18061) and enhance the security of your database connections.
For Executives
Implement the latest version of AWS Advanced JDBC Wrapper to mitigate the XXE vulnerability (CVE-2026-18061) and protect sensitive data from unauthorized access, ensuring compliance and maintaining customer trust.