← All Advisories

AWS Advanced JDBC Wrapper RemoteQueryCachePlugin deserializes cached Redis objects enabling code execution on application servers

Last refreshed2026-09-30

Status: UPDATED  |  Advisory ID: CVE-2026-14265

Key Details

CVECVE-2026-14265
CVSS Score / Version7.5 (High) / CVSS v3.1
Updated2026-07-09
CVSS VectorCVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H
CVSS Proseattack vector is network; attack complexity is high; privileges required is low; user interaction is none; scope is unchanged; confidentiality impact is high; integrity impact is high; availability impact is high.
Affected productsamazon advanced_jdbc_wrapper
Classified asCWE-502 (Deserialization of Untrusted Data)

Affected Products, Subsystems & Sectors

VendorProductAffected VersionsPatch Status
amazonadvanced_jdbc_wrapper
SubsystemsGeneral OT
SectorsMultiple

What to Know

Deserialization of untrusted data in the RemoteQueryCachePlugin in Amazon Web Services AWS Advanced JDBC Wrapper 3.3.0 through 4.0.0 might allow an actor with write access to the shared cache infrastructure to execute arbitrary code on application servers that read cached query results via a crafted serialized Java object. The RemoteQueryCachePlugin uses ObjectInputStream without class filtering when deserializing cached query results from Redis or Valkey, enabling gadget chain execution when cache entries are poisoned.

We recommend upgrading to AWS Advanced JDBC Wrapper version 4.0.1 or later. (NVD)

What to Do

Monitor amazon's web page for any future patch releases. See vendor advisory link below.

References

SourceReference
NVDhttps://nvd.nist.gov/vuln/detail/CVE-2026-14265
CVEhttps://www.cve.org/CVERecord?id=CVE-2026-14265
Vendor advisoryhttps://aws.amazon.com/security/security-bulletins/2026-051-aws/