A high-severity authorization flaw was disclosed in AWS's Amazon Connect Salesforce Lambda application, allowing attackers to perform privileged cloud actions beyond their assigned IAM permissions. The vulnerability, tracked as CVE-2026-94384, affects the sfExecuteAWSService Lambda function included with AmazonConnectSalesforceLambda versions 5.15 through 5.24.16. This function is utilized during the initial setup process, where it assists in integrating Amazon Connect contact-center services with Salesforce.
The flaw arises because the sfExecuteAWSService function fails to properly validate whether the caller is authorized to request the AWS operation specified in its parameters. An attacker who gains access to an IAM identity with the ability to invoke the function can abuse this issue to access AWS services, modify cloud resources, or carry out actions permitted by the Lambda execution role.
Organizations that leave it enabled after configuration may inadvertently expose a route for privilege escalation. This issue is particularly critical in environments where Lambda invocation permissions are broadly granted to developers, automation accounts, third-party integrations, or other IAM principals. Organizations using impacted versions should upgrade immediately and review whether the sfExecuteAWSService function remains necessary after the Amazon Connect and Salesforce integration is configured.
Teams should review IAM policies, Lambda resource policies, execution roles, CloudTrail logs, and cross-account trust settings for any unexpected usage.








![Top 10 Best Decentralized Identity Solutions in 2026 [Ranked & Scored]](http://cybersecuritynews.com/wp-content/uploads/2026/09/Best-Decentralized-Identity-Solutions-1.webp)


