Security Advisory Desk
unratedQCS priority 76/100Amazon Web Services

CVE-2026-108096: Improper authorization in query resolvers for SQL-backed models in AWS Amplify API Category

A security issue was found in AWS Amplify API's GraphQL query resolvers, where they did not properly check if a user was allowed to see certain data. This flaw could let an authenticated user access data owned by other users in the same application by crafting special queries. AWS has fixed this problem in newer software versions and advises users to upgrade.

QCS published 10/10/2026, 8:08:24 pm ISTVendor disclosure 9/10/2026, 11:43:24 pm ISTVerified 11/10/2026, 3:31:22 am ISTRevision 1

In plain language

What this advisory means

A security issue was found in AWS Amplify API's GraphQL query resolvers, where they did not properly check if a user was allowed to see certain data. This flaw could let an authenticated user access data owned by other users in the same application by crafting special queries. AWS has fixed this problem in newer software versions and advises users to upgrade.

Technical explanation

How the issue affects the environment

The vulnerability (CVE-2026-108096) concerns improper authorization handling in GraphQL query resolvers generated by the @aws-amplify/graphql-index-transformer used in AWS Amplify API Category. Specifically, these resolvers for SQL-backed data models sometimes fail to enforce ownership or authorization rules correctly. As a result, an authenticated remote user may craft GraphQL queries that allow reading records belonging to other users within the same application context. The issue impacts versions @aws-amplify/graphql-index-transformer >=2.2.0, @aws-amplify/graphql-api-construct >=1.4.0, and @aws-amplify/data-construct. AWS addressed this by releasing fixed versions: graphql-index-transformer 3.1.2, included in data-construct 1.17.4 and graphql-api-construct 1.21.4. There are no workarounds available other than upgrading and redeploying.

Operational impact

Why teams should care

If unpatched, this vulnerability could result in unauthorized data disclosure between users of the same application. This undermines data confidentiality, may violate privacy policies or regulations, and can damage user trust and the application's reputation. Organizations must upgrade to maintain secure data isolation among their users.

Immediate action

Upgrade to @aws-amplify/graphql-index-transformer version 3.1.2 or later, which is included in @aws-amplify/data-construct 1.17.4 and @aws-amplify/graphql-api-construct 1.21.4. After upgrading, redeploy your backend to ensure the fix is applied. Review any customized or forked code to incorporate these patches as well.

Affected and fixed releases

Affected versions@aws-amplify/graphql-index-transformer >=2.2.0, @aws-amplify/graphql-api-construct >=1.4.0, @aws-amplify/data-construct
Fixed versions@aws-amplify/graphql-index-transformer 3.1.2, @aws-amplify/data-construct 1.17.4, @aws-amplify/graphql-api-construct 1.21.4

Temporary risk reduction

No workarounds are available for this vulnerability. Immediate upgrading and redeployment are necessary to mitigate the risk.

Evidence and validation checklist

  • Official AWS Security Bulletin ID 2026-133-AWS published on 10/09/2026
  • Description specifying improper authorization in query resolvers generated by @aws-amplify/graphql-index-transformer
  • Impacted version numbers listed in the advisory
  • Remediation versions stated explicitly
  • Statement that no workarounds are available

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source