AWS Amplify Updates Fix Cross-Owner GraphQL Record Access

P2 — VALIDATE AND UPDATENot provided by the authority · Not provided by the authorityEXPLOITATION: NOT STATED

Quick Answer

AWS published 2026-133-AWS for CVE-2026-108096. Generated query resolvers for SQL-backed Amplify GraphQL models could let an authenticated user read another user's records. Upgrade all affected Amplify packages and redeploy the backend; AWS provides no workaround.

Update The Amplify Package Set And Redeploy Backends

What to do now: Inventory SQL-backed Amplify GraphQL APIs and all three affected package families, update them to the AWS-fixed releases or later, regenerate and redeploy each backend, validate owner-based authorization, and preserve deployment and access evidence.

Open the authoritative advisory

Last verified: 2026-10-10 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeAWS Amplify API Category packages for SQL-backed GraphQL models
Advisory2026-133-AWS
CVECVE-2026-108096
Authoritative release date2026-10-09 18:00:00 UTC (11:00 AM PDT in the AWS bulletin)
Authority revision date2026-10-09 18:00:00 UTC; no separate revision time is stated
Affected versions@aws-amplify/graphql-index-transformer 2.2.0 through versions before 3.1.2; @aws-amplify/graphql-api-construct 1.4.0 through versions before 1.21.4; and @aws-amplify/data-construct versions before 1.17.4.
Fixed version@aws-amplify/graphql-index-transformer 3.1.2, @aws-amplify/graphql-api-construct 1.21.4, and @aws-amplify/data-construct 1.17.4 or later, followed by backend redeployment
CVSS base scoreNot provided by the authority
CVSS severityNot provided by the authority
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

AWS updated authorization behavior in GraphQL query resolvers generated for SQL-backed models. The documented scenario requires an authenticated user of the same application and a crafted query; AWS does not publish a CVSS base score, severity, or exploitation finding.

What To Validate Now

  1. Inventory. Locate repositories, build manifests, lockfiles, pipelines, deployed backends, and forks using Amplify API Category with SQL-backed GraphQL models, and record the versions of all three affected packages.
  2. Establish applicability. Match the exact AWS package ranges and confirm that SQL-backed model query resolvers are deployed. Do not infer exposure from use of Amplify, AppSync, or GraphQL alone.
  3. Remediate. Upgrade @aws-amplify/graphql-index-transformer to 3.1.2, @aws-amplify/graphql-api-construct to 1.21.4, and @aws-amplify/data-construct to 1.17.4 or later; incorporate the fix into forks or derivatives; then regenerate and redeploy the backend.
  4. Validate. Confirm resolved dependency versions in the build and deployed artifact, test authorized and cross-owner query cases, verify deployment completion in every environment, and review available application and AppSync access evidence for unexpected cross-owner reads.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Updating a dependency without regenerating and redeploying the backend does not establish that the fixed resolver is active. Test schema generation and application queries before broad rollout, preserve relevant logs before retention expires, and rotate or notify only where investigation evidence supports that response.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.