→ Back to Home
Cloud Security

AWS Lambda IAM Bypass Flaw Hits CVSS 8.1 in AmazonConnectSalesforceLambda Integration

A high-severity IAM bypass vulnerability, tracked as CVE-2026-94384, has been identified in the `sfExecuteAWSService` Lambda function, which is part of AWS's `AmazonConnectSalesforceLambda` integration. This integration serves as the connective tissue between Amazon Connect contact centers and Salesforce Service Cloud Voice. The flaw allows any IAM principal capable of invoking this specific Lambda function to bypass their explicitly denied permissions and execute privileged actions. AWS quietly patched this issue in June 2026, but the security advisory was only published on September 22, 2026, with wider awareness among security professionals emerging only recently, around October 9-10, 2026. This vulnerability is significant for practitioners because it underscores the often-overlooked attack surface presented by managed integrations and serverless application repositories. While the affected component is specific, the underlying mechanism—a setup-only function with overly broad permissions and a privileged execution role—is a common pattern in cloud environments. An attacker exploiting this could achieve privilege escalation, potentially gaining access to sensitive data or control over other resources. The delay between the patch and widespread awareness also means that many organizations may have been unknowingly vulnerable for months. This incident particularly impacts AWS customers utilizing the Amazon Connect and Salesforce Service Cloud Voice integration, who must now urgently assess their exposure. This event fits into a broader, well-established trend in cloud security: the persistent challenge of Identity and Access Management (IAM) misconfigurations and the security implications of third-party components. Reports consistently highlight IAM failures and misconfigurations as leading causes of cloud breaches. The AWS Serverless Application Repository, while offering convenience, introduces a dependency management overhead that many security teams struggle to track effectively. This situation mirrors past incidents where vulnerabilities in widely used libraries or integrations have led to widespread exposure, even when the core cloud platform itself remains secure. The incident also highlights the ongoing struggle to maintain visibility and control over the rapidly expanding ecosystem of cloud services and their interconnected permissions. In practice, practitioners should treat applications from the Serverless Application Repository, or any similar third-party or managed integrations, as they would any other dependency in their software supply chain. This means actively searching every AWS account for deployments of `AmazonConnectSalesforceLambda` and immediately upgrading any instances running version 5.24.16 or earlier to version 5.26 or later. Beyond patching, it is crucial to audit the resource policies on the `sfExecuteAWSService` function in all affected accounts, even after upgrading, to ensure that overly broad invocation permissions are removed. This proactive approach to dependency management and rigorous IAM auditing is essential to mitigate risks that extend beyond the core cloud provider's shared responsibility model. This incident serves as a stark reminder that security posture is only as strong as its weakest link, often found in the layers built on top of the foundational cloud infrastructure.
#aws#iam#lambda#vulnerability#serverless#privilege escalation
Read original source