Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1336 CNY

100%

CVE-2026-86830— Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center

Quick assessment

Affected
AWS iam-identity-center-team
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

在 AWS IAM Identity Center 解决方案中的临时提升权限管理(TEAM)版本 1.5.1 之前的版本中,存在错误的权限分配问题。该缺陷可能允许拥有应用级别访问权限的已认证远程用户读取、批准、修改或撤销任意的访问请求,从而通过 TEAM 部署所连接的 AWS 账户获得非预期的临时提升权限。 该问题已在 TEAM 1.5.1 及更高版本中修复。建议升级到最新版本,并确保任何分支或衍生代码也已应用相应的补丁以纳入新修复。

CVSS 7.2 · High

Possible ATT&CK Techniques 1 AI

T1210 · Exploitation of Remote Services

Affected Version Matrix 1

VendorProduct Version RangeStatus
AWS iam-identity-center-team < 1.5.1 affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-86830

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center
Source: CVE Program / CVE List V5
Vulnerability Description
Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment. This issue has been addressed in TEAM version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H
Source: CVE Program / CVE List V5
Vulnerability Type
特权授予不正确
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
AWS iam-identity-center-team 0 ~ 1.5.1 -

II. Public POCs for CVE-2026-86830

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-86830

登录查看更多情报信息。

Vendor Advisories for CVE-2026-86830 (2)

Other References for CVE-2026-86830 (1)

IV. Related Vulnerabilities

V. Comments for CVE-2026-86830

No comments yet


Leave a comment