To remediate this issue, we recommend upgrading to version 5.26 or later. After setup is complete, either delete or disable the sfExecuteAWSService function. If you retain the function, restrict invocation to the intended IAM user only.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Tue, 22 Sep 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 22 Sep 2026 17:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API operations that their own IAM identity is explicitly denied, via invocation of a Lambda function that dispatches caller-supplied parameters to privileged service APIs without authorization validation. To remediate this issue, we recommend upgrading to version 5.26 or later. After setup is complete, either delete or disable the sfExecuteAWSService function. If you retain the function, restrict invocation to the intended IAM user only. | |
| Title | Missing Authorization in sfExecuteAWSService Lambda Dispatcher in Amazon Connect Salesforce Lambda | |
| First Time appeared |
Amazon
Amazon amazon-connect-salesforce-lambda |
|
| Weaknesses | CWE-862 | |
| CPEs | cpe:2.3:a:amazon:amazon-connect-salesforce-lambda:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Amazon
Amazon amazon-connect-salesforce-lambda |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-09-22T18:25:01.089Z
Reserved: 2026-09-21T13:00:33.350Z
Link: CVE-2026-94384
Updated: 2026-09-22T18:23:35.907Z
Status : Awaiting Analysis
Published: 2026-09-22T18:17:32.210
Modified: 2026-09-22T19:16:59.070
Link: CVE-2026-94384
No data.
OpenCVE Enrichment
Updated: 2026-09-22T19:13:31Z