AmazonConnectSalesforceLambda Authorization Bypass – Update Required
AmazonConnectSalesforceLambda versions 5.15–5.24.16 have a critical authorization flaw (CVE-2026-94384) in the sfExecuteAWSService function. An attacker with lambda:InvokeFunction permission can bypass IAM checks and execute privileged AWS operations they shouldn't access. If you're running affected versions, update immediately—this one's a real privilege escalation nightmare.
source: [aws/security-bulletin]