bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Wednesday, October 7, 2026

QnABot on AWS Authorization Bypass – Update Required if You Deployed Amazon Q Hook

QnABot on AWS versions 7.0.0–7.4.5 have a nasty authorization bypass (CVE-2026-105811) in the optional Amazon Q Business Lambda hook sample that could let authenticated users read arbitrary S3 objects. Good news: you're only affected if you manually deployed this hook—it doesn't ship by default. If you did deploy it, update QnABot to 7.4.6+ and redeploy the hook sample; updating QnABot alone won't cut it.

source: [aws/security-bulletin]