CVE-2026-8838 – Amazon Redshift connector for Python
CVSS 9.8
CRITICAL
“A critical code execution weakness in a database connector can expose entire cloud data environments.”
AWS released a patch for a critical vulnerability affecting the Amazon Redshift connector for Python. CVE-2026-8838 has a CVSS score of 9.8, which is Critical severity.
The vulnerability is tied to improper code generation and execution handling that could allow remote code execution in affected environments. The update strengthens execution safeguards and reduces the risk of attackers abusing database connectivity workflows to run unauthorized code against connected systems and cloud data infrastructure.
Key Details
- Attack Vector
- Network
- Attack Complexity
- Low
- Privileges Required
- None
- User Interaction
- None
- CWE Classification
- CWE-94
Patch this CVE on all your endpoints in under 5 minutes.
First 200 endpoints are free forever, scale as needed.