Skip to main content
Mallory
High

Privilege Escalation in AWS Advanced Go Wrapper GlobalDatabasePlugin

IdentifiersCVE-2026-11401CWE-426· Untrusted Search Path

CVE-2026-11401 is an untrusted search path vulnerability in the GlobalDatabasePlugin component of the AWS Advanced Go Wrapper for Amazon Aurora PostgreSQL. According to the provided content, a remote authenticated low-privilege attacker can create a crafted function that is later executed when another Amazon RDS user connects to the cluster through the affected wrapper. Because the plugin resolves or invokes functionality through an untrusted search path, the attacker-controlled function can be executed in the context of the connecting user, enabling privilege escalation to that user's database privileges, including rds_superuser.

Share:
For your environment

Are you exposed to this one?

Mallory correlates every CVE against your assets, your vendors, and active adversary campaigns. Know which vulnerabilities matter for you, not just which ones are loud.

ANALYST BRIEF

Impact, mitigation & remediation

What it means. What to do now. Patch path, mitigations, and the assume-compromise checklist.

Impact

What an attacker gets, and what they’ve been doing with it.

Successful exploitation allows a low-privilege authenticated actor to assume the effective privileges of another Amazon RDS user who connects through the affected wrapper. This can include escalation to highly privileged roles such as rds_superuser. As a result, the attacker may gain broad access to database contents, modify or destroy data, alter database objects and permissions, and potentially disrupt database availability, consistent with the reported high confidentiality, integrity, and availability impact.

Mitigation

If you can’t patch tonight, do this now.

If immediate upgrade is not possible, reduce exposure by limiting which users can create functions, restricting low-privilege accounts, and minimizing use of the affected wrapper for privileged connections until the fixed release is deployed. Monitor for unexpected or newly created crafted functions in the database and review connections made through the wrapper by privileged users. However, the primary remediation provided in the content is to upgrade to release 2026-05-26.

Remediation

Patch, then assume compromise.

Upgrade the AWS Advanced Go Wrapper to the release identified by AWS as containing the fix: release 2026-05-26. Validate that applications connecting to Amazon Aurora PostgreSQL clusters are using the updated wrapper version and redeploy affected services as needed.
PUBLIC EXPLOITS

Exploits

No public exploits tracked yet. Mallory keeps watching.

VALID 0 / 0 TOTALView more in app

No public exploit code observed for this vulnerability.

What this page doesn’t show

The version that knows your environment.

This page is what’s public. Mallory adds the parts that aren’t: which of your assets are affected, which adversaries are exploiting it right now, which detections to deploy, and what to do tonight.
Exposure mapping

Query your assets running an affected version, and investigate the blast radius.

Threat actor evidence

Every observed campaign linking this CVE to a named adversary.

Associated malware

Malware families riding this exploit, with evidence and IOCs.

Detection signatures

YARA, Sigma, Snort, and vendor rules, auto-deployed to your SIEM.

Vendor-by-vendor mapping

Cross-references every affected SKU, including bundled OEM variants.

Social activity5

Community discussion across Reddit, Mastodon, and other social sources.