CVE-2026-94384 vulnerability in Amazon Products
Published on September 22, 2026
Missing Authorization in sfExecuteAWSService Lambda Dispatcher in Amazon Connect Salesforce Lambda
Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API operations that their own IAM identity is explicitly denied, via invocation of a Lambda function that dispatches caller-supplied parameters to privileged service APIs without authorization validation.
To remediate this issue, we recommend upgrading to version 5.26 or later. After setup is complete, either delete or disable the sfExecuteAWSService function. If you retain the function, restrict invocation to the intended IAM user only.
Vulnerability Analysis
CVE-2026-94384 is exploitable with network access, and requires small amount of user privileges. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to have a high impact on confidentiality and integrity, and no impact on availability.
Weakness Type
What is an AuthZ Vulnerability?
The software does not perform an authorization check when an actor attempts to access a resource or perform an action.
CVE-2026-94384 has been classified to as an AuthZ vulnerability or weakness.
Products Associated with CVE-2026-94384
stack.watch emails you whenever new vulnerabilities are published in Amazon Connect Salesforce Lambda or Amazon Aws. Just hit a watch button to start following.
Affected Versions
amazon-connect-salesforce-lambda:- Version 5.15, <= 5.24.16 is affected.