Skip to main content

CVE-2026-94384 - Missing Authorization in AmazonConnectSalesforceLambda sfExecuteAWSService

0
High
VulnerabilityCVE-2026-94384cloud
Published: 09/22/2026 (09/22/2026, 17:10:17 UTC)
Source: AWS Security Bulletins

Description

CVE-2026-94384 is a missing authorization vulnerability in the sfExecuteAWSService Lambda function of the Amazon Connect Salesforce Lambda application. This function, used only during initial setup, improperly dispatches caller-supplied parameters to privileged AWS service APIs without validating authorization. Consequently, any IAM principal with lambda:InvokeFunction permission on this function can perform AWS operations beyond their own IAM permissions. Versions from 5.15 through 5.24.16 are affected. The issue is remediated by upgrading to version 5.26 or later, deleting or disabling the vulnerable function after setup, or restricting invocation permissions tightly.

Affected software

Affected versions
>=5.15 <=5.24.16

AI-Powered Analysis

Machine-generated threat intelligence

AILast updated: 09/22/2026, 17:15:01 UTC

Technical Analysis

Amazon Connect Salesforce Lambda (AmazonConnectSalesforceLambda) contains a missing authorization vulnerability (CVE-2026-94384) in the sfExecuteAWSService Lambda function. This function is designed to integrate Amazon Connect with Salesforce and is used only during initial setup. The vulnerability arises because the function forwards caller-supplied parameters to privileged AWS service APIs without validating the caller's authorization. As a result, any IAM principal granted lambda:InvokeFunction permission on this function can perform AWS operations that their own IAM permissions would normally deny. The affected versions are from 5.15 up to and including 5.24.16. AWS recommends upgrading to version 5.26 or later. Additionally, after setup, the sfExecuteAWSService function should be deleted or disabled. If retained, invocation permissions should be restricted exclusively to the IAM user used by the CTI Adapter, and cross-account invocation should be limited accordingly. Verification steps include confirming the function is disabled or deleted or that invocation permissions are properly restricted.

Potential Impact

An attacker or user with lambda:InvokeFunction permission on the vulnerable sfExecuteAWSService function can bypass their IAM permission restrictions and perform privileged AWS operations. This elevates the risk of unauthorized actions within the AWS environment, potentially leading to privilege escalation or unauthorized resource manipulation. The vulnerability affects only the specified versions of the AmazonConnectSalesforceLambda application and only during or after initial setup if the vulnerable function remains enabled and improperly secured.

Mitigation Recommendations

A fix is available by upgrading AmazonConnectSalesforceLambda to version 5.26 or later. After completing setup, delete or disable the sfExecuteAWSService Lambda function to eliminate the vulnerability. If the function must be retained, restrict lambda:InvokeFunction permission on it exclusively to the single IAM user used by the CTI Adapter, denying all other principals via service control policies or permission boundaries. Also, set the SalesforceExecuteAWSServiceUser parameter to this IAM user to limit cross-account invocation. Verification should confirm the function is disabled or deleted or that invocation permissions are tightly restricted as described.

Pro Console: star threats, build custom feeds, automate alerts via Slack, email & webhooks.Upgrade to Pro

Technical Details

Classification
{"confidence":0.88,"severitySource":"default","classifier":"rss-v2"}
Article Source
{"url":"https://aws.amazon.com/security/security-bulletins/rss/2026-115-aws/","fetched":true,"fetchedAt":"2026-09-22T17:14:55.904Z","wordCount":286}

Threat ID: 6ab2b78ff7a7c541067cda44

Added to database: 09/22/2026, 17:14:55 UTC

Last enriched: 09/22/2026, 17:15:01 UTC

Last updated: 09/22/2026, 17:15:01 UTC

Views: 1

Community Reviews

0 reviews

Crowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.

Sort by
Loading community insights…

Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.

Actions

PRO

Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.

Please log in to the Console to use AI analysis features.

Need more coverage?

Upgrade to Pro Console for AI refresh and higher limits.

For incident response and remediation, OffSeq services can help resolve threats faster.

Latest Threats

Breach by OffSeqOFFSEQFRIENDS — 25% OFF

Check if your credentials are on the dark web

Instant breach scanning across billions of leaked records. Free tier available.

Scan now
OffSeq TrainingCredly Certified

Lead Pen Test Professional

Technical5-day eLearningPECB Accredited
View courses