Vulnerability
Published 2026-09-22
Verified 2026-09-27

AWS AmazonConnectSalesforceLambda CVE-2026-94384 (CVSS 8.1): sfExecuteAWSService IAM privilege proxy — fix 5.26

AWS Security Bulletin 2026-115-AWS (Publication 22 September 2026 10:00 AM PDT) documents CVE-2026-94384: missing authorization in Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLambda) sfExecuteAWSService before 5.26. Any IAM principal with lambda:InvokeFunction on the function can escalate and call AWS APIs allowed by the function's privileged execution role even when their own IAM policy denies those actions — the Lambda becomes a privileged parameter-dispatch proxy. Amazon CVSS 3.1 8.1 High (CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N); CVSS 4.0 6.4 Medium. Affected SAR app versions 5.15 through <5.26 (CSN also cites through 5.24.16). Remediation: upgrade to 5.26 or later; after setup delete or disable sfExecuteAWSService, or restrict InvokeFunction to the intended CTI Adapter IAM user only. Credit: Chang Li (Xidian University) via CVD. Primary: AWS bulletin 2026-115-AWS; metadata: CVE.report; wire: Cyber Security News 23 Sep 2026.

Product
Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLambda) — sfExecuteAWSService
Versions
Affected before 5.26 (reported 5.15–5.24.16 range in secondary coverage). Upgrade to 5.26+; then delete/disable sfExecuteAWSService or lock InvokeFunction.
CVSS
(CVSS 3.1 High, Amazon); 6.4 (CVSS 4.0 Medium, Amazon)
Exploited in Australia?
unknown
Patch to
Upgrade AmazonConnectSalesforceLambda to 5.26+; delete/disable sfExecuteAWSService post-setup or restrict lambda:InvokeFunction to intended IAM only

Primary: AWS Security Bulletin 2026-115-AWS — CVE-2026-94384 (22 Sep 2026) · Vendor: AWS — 2026-115-AWS · CVE: CVE-2026-94384 · CVE.report — CVE-2026-94384; also Cyber Security News 23 Sep 2026

vulnerabilities cloud identity