Skip to main content
Vulnerability Database/CVE-2026-94384

CVE-2026-94384: Amazon Connect Salesforce Lambda Privilege Escalation

CVE-2026-94384 is a privilege escalation flaw in Amazon Connect Salesforce Lambda before version 5.26 that lets attackers bypass IAM restrictions. This post explains its impact, affected versions, and mitigation steps.

Published:

CVE-2026-94384 Overview

CVE-2026-94384 is a missing authorization vulnerability [CWE-862] in the Amazon amazon-connect-salesforce-lambda integration prior to version 5.26. The affected sfExecuteAWSService Lambda function dispatches caller-supplied parameters to privileged AWS service APIs without validating authorization. Any AWS Identity and Access Management (IAM) principal with lambda:InvokeFunction permission on the affected function can escalate privileges. The attacker can invoke AWS API operations that their own IAM identity is explicitly denied. Amazon addressed the issue in release v5.26 and recommends deleting or disabling the sfExecuteAWSService function after setup completes.

Critical Impact

Authenticated IAM principals can bypass explicit IAM denies and execute privileged AWS API calls through the Lambda function, enabling cross-account or intra-account privilege escalation.

Affected Products

  • Amazon amazon-connect-salesforce-lambda versions prior to 5.26
  • Amazon Connect Salesforce CTI integration deployments using sfExecuteAWSService
  • AWS environments where the vulnerable Lambda function is deployed with broad invocation permissions

Discovery Timeline

  • 2026-09-22 - CVE-2026-94384 published to the National Vulnerability Database (NVD)
  • 2026-09-22 - Last updated in NVD database

Technical Details for CVE-2026-94384

Vulnerability Analysis

The amazon-connect-salesforce-lambda package provides integration between Amazon Connect and Salesforce. It ships a helper Lambda function named sfExecuteAWSService that accepts caller-supplied parameters and forwards them to AWS service APIs. The function performs the API call using its own execution role rather than the invoker's identity.

The function does not validate whether the invoking principal is authorized to perform the requested action. Any IAM principal holding lambda:InvokeFunction on this function inherits the effective permissions of the Lambda execution role. This produces a confused-deputy condition where the Lambda acts on behalf of the caller without honoring the caller's IAM policy denies.

Explicit denies attached to an invoker's IAM identity provide no protection because the API call is executed under the Lambda role's context. The impact scales with the privileges granted to the Lambda execution role.

Root Cause

The root cause is missing authorization validation [CWE-862] inside the sfExecuteAWSService handler. The handler treats the invocation as pre-authorized and forwards service, action, and parameter fields to the AWS SDK without checking the caller's identity or the requested operation against an allow list.

Attack Vector

An authenticated IAM principal with lambda:InvokeFunction permission on the affected function invokes it with crafted parameters specifying a privileged AWS service and API action. The Lambda executes the request under its execution role, returning results to the caller. This enables privilege escalation across services that the Lambda role can reach, including operations explicitly denied to the invoker.

No verified public exploit code is available. See the GitHub Security Advisory GHSA-c9j2-qjfv-mm4p for advisory-level technical detail.

Detection Methods for CVE-2026-94384

Indicators of Compromise

  • CloudTrail events showing Invoke calls against the sfExecuteAWSService Lambda from IAM principals outside the intended Salesforce integration identity.
  • AWS API calls originating from the Lambda execution role that target services unrelated to the Amazon Connect and Salesforce integration workflow.
  • Successful privileged API actions performed by the Lambda role shortly after an unusual invocation pattern from a low-privilege principal.

Detection Strategies

  • Enumerate all principals whose IAM policies grant lambda:InvokeFunction on the sfExecuteAWSService function using IAM Access Analyzer.
  • Correlate CloudTrail Invoke events on the affected function with subsequent AWS API calls made by the Lambda execution role within the same request context.
  • Alert on invocations of sfExecuteAWSService where the payload references sensitive services such as IAM, KMS, STS, or S3 administrative APIs.

Monitoring Recommendations

  • Enable CloudTrail data events for Lambda invocations and forward logs to a centralized analytics platform for continuous review.
  • Baseline the expected invoker identity and payload shape for sfExecuteAWSService, then alert on deviations.
  • Track the Lambda execution role's API activity in GuardDuty and flag anomalous service usage or cross-account calls.

How to Mitigate CVE-2026-94384

Immediate Actions Required

  • Upgrade amazon-connect-salesforce-lambda to version 5.26 or later in all affected deployments.
  • Delete or disable the sfExecuteAWSService function after setup completes, as recommended by the vendor.
  • If the function must be retained, restrict lambda:InvokeFunction to the single intended IAM user through a resource-based policy.
  • Scope the Lambda execution role to the minimum AWS service actions required for the integration.

Patch Information

Amazon released the fix in Amazon Connect Salesforce Lambda Release v5.26. Additional vendor guidance is available in the AWS Security Bulletin 2026-115 and the GitHub Security Advisory GHSA-c9j2-qjfv-mm4p.

Workarounds

  • Attach a Lambda resource-based policy that permits invocation only from the specific IAM user tied to the Salesforce integration.
  • Apply a Service Control Policy (SCP) that denies sensitive API actions from the Lambda execution role's context.
  • Rotate any credentials or secrets that may have been accessible through the Lambda execution role prior to remediation.
bash
# Restrict invocation of sfExecuteAWSService to a single IAM user
aws lambda add-permission \
  --function-name sfExecuteAWSService \
  --statement-id RestrictToIntegrationUser \
  --action lambda:InvokeFunction \
  --principal arn:aws:iam::<ACCOUNT_ID>:user/<INTEGRATION_USER>

# Or remove the function entirely once setup is complete
aws lambda delete-function --function-name sfExecuteAWSService

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.