CVE-2026-94384 - Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService
CVE-2026-94384 is a missing authorization vulnerability in the sfExecuteAWSService Lambda function of the Amazon Connect Salesforce Lambda application. This function, used only during initial setup, improperly dispatches caller-supplied parameters to privileged AWS service APIs without validating authorization. Consequently, any IAM principal with lambda:InvokeFunction permission on this function can perform AWS operations beyond their own IAM permissions. Versions from 5.15 through 5.24.16 are affected. The issue is remediated by upgrading to version 5.26 or later, deleting or disabling the vulnerable function after setup, or restricting invocation permissions tightly.
AI Analysis
Technical Summary
Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLambda) contains a missing authorization vulnerability (CVE-2026-94384) in the sfExecuteAWSService Lambda function. This function is designed to integrate Amazon Connect with Salesforce and is used only during initial setup. The vulnerability arises because the function forwards caller-supplied parameters to privileged AWS service APIs without validating the caller's authorization. As a result, any IAM principal granted lambda:InvokeFunction permission on this function can perform AWS operations that their own IAM permissions would normally deny. The affected versions are from 5.15 up to and including 5.24.16. AWS recommends upgrading to version 5.26 or later. Additionally, after setup, the sfExecuteAWSService function should be deleted or disabled. If retained, invocation permissions should be restricted exclusively to the IAM user used by the CTI Adapter, and cross-account invocation should be limited accordingly. Verification steps include confirming the function is disabled or deleted or that invocation permissions are properly restricted.
Potential Impact
An attacker or user with lambda:InvokeFunction permission on the vulnerable sfExecuteAWSService function can bypass their IAM permission restrictions and perform privileged AWS operations. This elevates the risk of unauthorized actions within the AWS environment, potentially leading to privilege escalation or unauthorized resource manipulation. The vulnerability affects only the specified versions of the AmazonConnectSalesforceLambda application and only during or after initial setup if the vulnerable function remains enabled and improperly secured.
Mitigation Recommendations
A fix is available by upgrading AmazonConnectSalesforceLambda to version 5.26 or later. After completing setup, delete or disable the sfExecuteAWSService Lambda function to eliminate the vulnerability. If the function must be retained, restrict lambda:InvokeFunction permission on it exclusively to the single IAM user used by the CTI Adapter, denying all other principals via service control policies or permission boundaries. Also, set the SalesforceExecuteAWSServiceUser parameter to this IAM user to limit cross-account invocation. Verification should confirm the function is disabled or deleted or that invocation permissions are tightly restricted as described.
CVE-2026-94384 - Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService
Description
CVE-2026-94384 is a missing authorization vulnerability in the sfExecuteAWSService Lambda function of the Amazon Connect Salesforce Lambda application. This function, used only during initial setup, improperly dispatches caller-supplied parameters to privileged AWS service APIs without validating authorization. Consequently, any IAM principal with lambda:InvokeFunction permission on this function can perform AWS operations beyond their own IAM permissions. Versions from 5.15 through 5.24.16 are affected. The issue is remediated by upgrading to version 5.26 or later, deleting or disabling the vulnerable function after setup, or restricting invocation permissions tightly.
Affected software
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLambda) contains a missing authorization vulnerability (CVE-2026-94384) in the sfExecuteAWSService Lambda function. This function is designed to integrate Amazon Connect with Salesforce and is used only during initial setup. The vulnerability arises because the function forwards caller-supplied parameters to privileged AWS service APIs without validating the caller's authorization. As a result, any IAM principal granted lambda:InvokeFunction permission on this function can perform AWS operations that their own IAM permissions would normally deny. The affected versions are from 5.15 up to and including 5.24.16. AWS recommends upgrading to version 5.26 or later. Additionally, after setup, the sfExecuteAWSService function should be deleted or disabled. If retained, invocation permissions should be restricted exclusively to the IAM user used by the CTI Adapter, and cross-account invocation should be limited accordingly. Verification steps include confirming the function is disabled or deleted or that invocation permissions are properly restricted.
Potential Impact
An attacker or user with lambda:InvokeFunction permission on the vulnerable sfExecuteAWSService function can bypass their IAM permission restrictions and perform privileged AWS operations. This elevates the risk of unauthorized actions within the AWS environment, potentially leading to privilege escalation or unauthorized resource manipulation. The vulnerability affects only the specified versions of the AmazonConnectSalesforceLambda application and only during or after initial setup if the vulnerable function remains enabled and improperly secured.
Mitigation Recommendations
A fix is available by upgrading AmazonConnectSalesforceLambda to version 5.26 or later. After completing setup, delete or disable the sfExecuteAWSService Lambda function to eliminate the vulnerability. If the function must be retained, restrict lambda:InvokeFunction permission on it exclusively to the single IAM user used by the CTI Adapter, denying all other principals via service control policies or permission boundaries. Also, set the SalesforceExecuteAWSServiceUser parameter to this IAM user to limit cross-account invocation. Verification should confirm the function is disabled or deleted or that invocation permissions are tightly restricted as described.
Technical Details
- Classification
- {"confidence":0.88,"severitySource":"default","classifier":"rss-v2"}
- Article Source
- {"url":"https://aws.amazon.com/security/security-bulletins/rss/2026-115-aws/","fetched":true,"fetchedAt":"2026-09-22T17:14:55.904Z","wordCount":286}
Threat ID: 6ab2b78ff7a7c541067cda44
Added to database: 09/22/2026, 17:14:55 UTC
Last enriched: 09/22/2026, 17:15:01 UTC
Last updated: 09/22/2026, 17:15:01 UTC
Views: 1
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.