AWS Latest Bulletins
Follow
CVE-2026-94384 - Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService
Bulletin ID: 2026-115-AWSScope: AWSContent Type: Important (requires attention)Publication Date: 09/22/2026 10:00 AM PDTDescription:Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLambda) is a Serverless Application Repository application that provides Lambda functions for integrating Amazon Connect with Salesforce. We identified CVE-2026-94384, a missing authorization issue in the sfExecuteAWSService Lambda function, which is used only during initial setup. The function dispatches caller-supplied parameters to privileged AWS service APIs without validating the caller's authorization. As a result, an IAM principal with lambda:InvokeFunction permission on the function can perform AWS operations that their own IAM permissions would otherwise deny.Impacted versions: >= 5.15 AND <= 5.24.16Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.