A vulnerability, which was classified as problematic, was found in DuckDB. Affected by this vulnerability is the function load_aws_credentials of the component AWS extension. Executing a manipulation of the argument redact_secret can lead to missing encryption of sensitive data.

This vulnerability is registered as CVE-2026-58139. It is possible to launch the attack remotely. No exploit is available.

It is advisable to implement a patch to correct this issue.