← Back to feed
Vulnerabilities & PatchesEmerging1 sourceSep 23, 2026 · 14:23via Cyber Security News

AWS Lambda Flaw Lets Attackers Bypass IAM Permissions and Access Cloud Services

Brief

AWS disclosed a high-severity authorization flaw in its Amazon Connect Salesforce Lambda application that could let attackers perform privileged cloud actions beyond their assigned IAM permissions.

The vulnerability, tracked as CVE-2026-94384, affects the sfExecuteAWSService Lambda function included with AmazonConnectSalesforceLambda versions 5. 15 through 5.

  • 16.

AmazonConnectSalesforceLambda is a Serverless Application Repository application designed to integrate Amazon Connect contact-center services with Salesforce.

The affected Lambda function is used during the initial setup process, where it helps the integration perform AWS service operations required for configuration.

The flaw exists because the sfExecuteAWSService function does not properly verify whether the caller is authorized to request the AWS operation supplied in its parameters.

Read more on Cyber Security News