Amazon Connect Salesforce Lambda Amazon Connect Salesforce Lambda

Don't miss out!

Thousands of developers use stack.watch to stay informed.
Get an email whenever new security vulnerabilities are reported in Amazon Connect Salesforce Lambda.

By the Year

In 2026 there have been 1 vulnerability in Amazon Connect Salesforce Lambda with an average score of 8.1 out of ten.

Year Vulnerabilities Average Score
2026 1 8.10

It may take a day or so for new Amazon Connect Salesforce Lambda vulnerabilities to show up in the stats or in the list of recent security vulnerabilities. Additionally vulnerabilities may be tagged under a different product or component name.

Recent Amazon Connect Salesforce Lambda Security Vulnerabilities

Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API operations
CVE-2026-94384 8.1 - High - September 22, 2026

Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API operations that their own IAM identity is explicitly denied, via invocation of a Lambda function that dispatches caller-supplied parameters to privileged service APIs without authorization validation. To remediate this issue, we recommend upgrading to version 5.26 or later. After setup is complete, either delete or disable the sfExecuteAWSService function. If you retain the function, restrict invocation to the intended IAM user only.

AuthZ

Stay on top of Security Vulnerabilities

Want an email whenever new vulnerabilities are published for Amazon Connect Salesforce Lambda or by Amazon? Click the Watch button to subscribe.

Amazon
Vendor

subscribe