Skip to content
  • Home
  • Cyber Map
  • About Us – Contact
  • Disclaimer
  • Terms and Rules
  • Privacy Policy
Cyber Web Spider Blog – News

Cyber Web Spider Blog – News

Globe Threat Map provides a real-time, interactive 3D visualization of global cyber threats. Monitor DDoS attacks, malware, and hacking attempts with geo-located arcs on a rotating globe. Stay informed with live logs and archive stats.

  • Home
  • Cyber Map
  • Cyber Security News
  • Security Week News
  • The Hacker News
  • How To?
  • Toggle search form
AWS Lambda Vulnerability Risks Unauthorized Cloud Access

AWS Lambda Vulnerability Risks Unauthorized Cloud Access

Posted on September 23, 2026 By CWS

A critical security issue has been identified in AWS’s Amazon Connect Salesforce Lambda application, posing risks of unauthorized cloud operations. The flaw, designated as CVE-2026-94384, allows attackers to perform actions in the cloud beyond their allocated IAM permissions.

Affected Lambda Function and Versions

The vulnerability affects the sfExecuteAWSService Lambda function in AmazonConnectSalesforceLambda, specifically versions 5.15 through 5.24.16. This application is designed to facilitate the integration between Amazon Connect and Salesforce, providing a seamless connection for contact-center services.

During the initial setup phase, this Lambda function helps execute necessary AWS service operations. However, due to inadequate authorization checks, the function fails to confirm if a caller is authorized to request the AWS operations specified in its parameters.

Potential Security Risks

The flawed function can inadvertently send parameters controlled by the caller to AWS service APIs using its privileged execution role. This loophole creates a potential bypass of permission checks, allowing IAM users with lambda:InvokeFunction rights to execute operations that their IAM policies would typically restrict.

As a result, the vulnerable Lambda function could be exploited as a high-privilege proxy, enabling attackers to access AWS services, alter cloud resources, or perform actions allowed by the Lambda execution role. The severity of this issue depends on the permissions assigned to the function’s role and the available AWS APIs.

Mitigation and Recommendations

AWS has released a new version, AmazonConnectSalesforceLambda 5.26, to address the vulnerability. Organizations using affected versions are urged to upgrade immediately and reassess the necessity of the sfExecuteAWSService function post-integration.

Following setup, AWS advises disabling or deleting the sfExecuteAWSService function to prevent unnecessary exposure to privilege escalation. If it must remain active, access should be restricted to a single IAM user associated with the CTI Adapter, barring all other users and roles from invoking it.

To enhance security, organizations can implement AWS Service Control Policies or permission boundaries to explicitly deny invocation access for unauthorized principals. Configuring the SalesforceExecuteAWSServiceUser parameter to match the CTI Adapter’s IAM user can further limit cross-account invocation risks.

Conclusion and Future Outlook

Security teams are encouraged to verify the removal or disabling of the vulnerable function post-setup. Regular checks of IAM policies, Lambda resource policies, execution roles, and CloudTrail logs are vital to detect any unusual activities.

In recognition of the vulnerability’s discovery, AWS credited Chang Li from Xidian University, who reported the issue through a coordinated vulnerability disclosure process. This incident underscores the importance of vigilant security practices and timely updates to safeguard cloud environments.

Cyber Security News Tags:Amazon Connect, Authorization, AWS, cloud computing, cloud security, CVE-2026-94384, Cybersecurity, data protection, IAM permissions, Lambda, privilege escalation, Salesforce, security flaw, serverless applications, Vulnerability

Post navigation

Previous Post: Armenian National Sentenced for Ryuk Ransomware Attacks
Next Post: New PamStealer Malware Targets Mac Passwords

Related Posts

New Tech Support Scam with Microsoft’s Logo Tricks Users to Steal Login Credentials New Tech Support Scam with Microsoft’s Logo Tricks Users to Steal Login Credentials Cyber Security News
CISA Highlights Exploited Langflow Code Injection Flaw CISA Highlights Exploited Langflow Code Injection Flaw Cyber Security News
Windows 11 to Hide BSOD Crash Errors on Public Displays Windows 11 to Hide BSOD Crash Errors on Public Displays Cyber Security News
New Tool Analyzes LinkedIn Contacts with Epstein Files New Tool Analyzes LinkedIn Contacts with Epstein Files Cyber Security News
Hackers Exploit Windows File Explorer for Malware Delivery Hackers Exploit Windows File Explorer for Malware Delivery Cyber Security News
2025 Insider Risk Report Finds Most Organizations Struggle to Detect and Predict Insider Risks 2025 Insider Risk Report Finds Most Organizations Struggle to Detect and Predict Insider Risks Cyber Security News

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Recent Posts

  • New PamStealer Malware Targets Mac Passwords
  • AWS Lambda Vulnerability Risks Unauthorized Cloud Access
  • Armenian National Sentenced for Ryuk Ransomware Attacks
  • Unpatched Ubuntu Bug Allows Host-Root Container Escape
  • IBM Patches Critical FTM Vulnerabilities Affecting Payment Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Archives

  • September 2026
  • August 2026
  • July 2026
  • June 2026
  • May 2026
  • April 2026
  • March 2026
  • February 2026
  • January 2026
  • December 2025
  • November 2025
  • October 2025
  • September 2025
  • August 2025
  • July 2025
  • June 2025
  • May 2025

Recent Posts

  • New PamStealer Malware Targets Mac Passwords
  • AWS Lambda Vulnerability Risks Unauthorized Cloud Access
  • Armenian National Sentenced for Ryuk Ransomware Attacks
  • Unpatched Ubuntu Bug Allows Host-Root Container Escape
  • IBM Patches Critical FTM Vulnerabilities Affecting Payment Systems

Pages

  • About Us – Contact
  • Disclaimer
  • Privacy Policy
  • Terms and Rules

Categories

  • Cyber Security News
  • How To?
  • Security Week News
  • The Hacker News

Copyright © 2026 Cyber Web Spider Blog – News.

Powered by PressBook Masonry Dark