AWS Amplify Updates Fix Cross-Owner GraphQL Record Access
Quick Answer
AWS published 2026-133-AWS for CVE-2026-108096. Generated query resolvers for SQL-backed Amplify GraphQL models could let an authenticated user read another user's records. Upgrade all affected Amplify packages and redeploy the backend; AWS provides no workaround.
Update The Amplify Package Set And Redeploy Backends
What to do now: Inventory SQL-backed Amplify GraphQL APIs and all three affected package families, update them to the AWS-fixed releases or later, regenerate and redeploy each backend, validate owner-based authorization, and preserve deployment and access evidence.
Last verified: 2026-10-10 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | AWS Amplify API Category packages for SQL-backed GraphQL models |
|---|---|
| Advisory | 2026-133-AWS |
| CVE | CVE-2026-108096 |
| Authoritative release date | 2026-10-09 18:00:00 UTC (11:00 AM PDT in the AWS bulletin) |
| Authority revision date | 2026-10-09 18:00:00 UTC; no separate revision time is stated |
| Affected versions | @aws-amplify/graphql-index-transformer 2.2.0 through versions before 3.1.2; @aws-amplify/graphql-api-construct 1.4.0 through versions before 1.21.4; and @aws-amplify/data-construct versions before 1.17.4. |
| Fixed version | @aws-amplify/graphql-index-transformer 3.1.2, @aws-amplify/graphql-api-construct 1.21.4, and @aws-amplify/data-construct 1.17.4 or later, followed by backend redeployment |
| CVSS base score | Not provided by the authority |
| CVSS severity | Not provided by the authority |
| Exploitation status | Not stated by the authority; no exploitation claim is inferred. |
What Changed
AWS updated authorization behavior in GraphQL query resolvers generated for SQL-backed models. The documented scenario requires an authenticated user of the same application and a crafted query; AWS does not publish a CVSS base score, severity, or exploitation finding.
What To Validate Now
- Inventory. Locate repositories, build manifests, lockfiles, pipelines, deployed backends, and forks using Amplify API Category with SQL-backed GraphQL models, and record the versions of all three affected packages.
- Establish applicability. Match the exact AWS package ranges and confirm that SQL-backed model query resolvers are deployed. Do not infer exposure from use of Amplify, AppSync, or GraphQL alone.
- Remediate. Upgrade @aws-amplify/graphql-index-transformer to 3.1.2, @aws-amplify/graphql-api-construct to 1.21.4, and @aws-amplify/data-construct to 1.17.4 or later; incorporate the fix into forks or derivatives; then regenerate and redeploy the backend.
- Validate. Confirm resolved dependency versions in the build and deployed artifact, test authorized and cross-owner query cases, verify deployment completion in every environment, and review available application and AppSync access evidence for unexpected cross-owner reads.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Updating a dependency without regenerating and redeploying the backend does not establish that the fixed resolver is active. Test schema generation and application queries before broad rollout, preserve relevant logs before retention expires, and rotate or notify only where investigation evidence supports that response.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

