Status: UPDATED | Advisory ID: CVE-2026-14265
| CVE | CVE-2026-14265 |
| CVSS Score / Version | 7.5 (High) / CVSS v3.1 |
| Updated | 2026-07-09 |
| CVSS Vector | CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H |
| CVSS Prose | attack vector is network; attack complexity is high; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high. |
| Affected products | amazon advanced_jdbc_wrapper |
| Classified as | CWE-502 (Deserialization of Untrusted Data) |
| Vendor | Product | Affected Versions | Patch Status |
|---|---|---|---|
| amazon | advanced_jdbc_wrapper |
| Subsystems | General OT |
| Sectors | Multiple |
Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the shared cache infrastructure to execute arbitrary code on application servers that read cached query results via a crafted serialized Java object. The RemoteQueryCachePlugin uses ObjectInputStream without class filtering when deserializing cached query results from Redis or Valkey, enabling gadget chain execution when cache entries are poisoned.
We recommend upgrading to AWS Advanced JDBC Wrapper version 4.0.1 or later. (NVD)
Monitor amazon's web page for any future patch releases. See vendor advisory link below.
| Source | Reference |
|---|---|
| NVD | https://nvd.nist.gov/vuln/detail/CVE-2026-14265 |
| CVE | https://www.cve.org/CVERecord?id=CVE-2026-14265 |
| Vendor advisory | https://aws.amazon.com/security/security-bulletins/2026-051-aws/ |