XXE in AWS Advanced JDBC Wrapper 3.3.04.2.0 RemoteQueryCachePlugin
CVE-2026-18061 Published on September 11, 2026
Improper Restriction of XML External Entity References in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin
Improper restriction of XML external entity references in the RemoteQueryCachePlugin in AWS Advanced JDBC Wrapper 3.3.0 through 4.2.0 might allow an actor with write access to the shared cache infrastructure to disclose sensitive files from application hosts that read cached query results, including stored database and IAM role credentials, via crafted XML data in a cached column value.
To remediate this issue, users should upgrade to version 4.3.0 or later.
Vulnerability Analysis
CVE-2026-18061 can be exploited with network access, and requires small amount of user privileges. This vulnerability is consided to have a high level of attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality, with no impact on integrity, and a small impact on availability.
Weakness Type
What is a XXE Vulnerability?
The software processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.
CVE-2026-18061 has been classified to as a XXE vulnerability or weakness.
Products Associated with CVE-2026-18061
Want to know whenever a new CVE is published for Aws Advanced Jdbc Wrapper? stack.watch will email you.
Affected Versions
AWS Advanced JDBC Wrapper:- Version 3.3.0, <= 4.2.0 is affected.