CVE-2026-86830

Source
https://cve.org/CVERecord?id=CVE-2026-86830
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86830.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-86830
Aliases
  • GHSA-6x87-mjv8-mgvj
Published
2026-09-14T18:00:41Z
Modified
2026-09-19T11:45:37Z
Severity
  • 8.6 (High) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N CVSS Calculator
Summary
Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center
Details

Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment.

This issue has been addressed in TEAM version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Database specific
{
    "cna_assigner": "AMZN",
    "cwe_ids": [
        "CWE-266"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86830.json"
}
References

Affected packages

Git / github.com/aws-samples/iam-identity-center-team

Affected ranges

Type
GIT
Repo
https://github.com/aws-samples/iam-identity-center-team
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events": [
        {
            "introduced": "0"
        },
        {
            "fixed": "1.5.1"
        }
    ],
    "source": [
        "AFFECTED_FIELD",
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

1.*
1.5.0
v.*
v.1.2.0
v1.*
v1.0.1
v1.0.2
v1.0.3
v1.0.4
v1.0.5
v1.0.6
v1.1.0
v1.1.1
v1.1.2
v1.2.1
v1.2.2
v1.3.0
v1.4.0
v1.4.1
v1.4.2

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86830.json"