VYPR

amazon-connect-salesforce-lambda

by Amazon

CVEs (1)

  • CVE-2026-94384HigSep 22, 2026
    risk 0.53cvss 8.1epss

    Missing authorization in Amazon amazon-connect-salesforce-lambda before 5.26 allows any IAM principal with lambda:InvokeFunction permission on the affected function to escalate privileges and perform AWS API operations that their own IAM identity is explicitly denied, via…