CVE-2026-58139

MEDIUM

DuckDB AWS Extension Security Policy Bypass via load_aws_credentials Procedure

Title source: cna
STIX 2.1

Description

The DuckDB AWS extension for DuckDB contains a security policy bypass vulnerability that allows any database user with SQL execution permissions to extract plaintext AWS credentials by calling the load_aws_credentials function with the redact_secret parameter set to false, circumventing the database-wide allow_unredacted_secrets=false policy. Attackers can invoke this single function to retrieve the underlying AWS credential chain including access_key_id, secret_access_key, session_token, and region in plaintext, which are immediately valid against AWS APIs and particularly impactful in managed environments where pg_duckdb is preloaded and an AWS credential chain such as IMDSv2, IRSA, ECS task role, or EC2 instance role is reachable.

Scores

CVSS v3 6.5
EPSS 0.0029
EPSS Percentile 21.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-863
Status published
Products (1)
duckdb/duckdb-aws < 7d04119ee8d3f8836e278f0e8cbf21827ff5338b
Published Aug 03, 2026
Tracked Since Aug 04, 2026