Description
Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment.



This issue has been addressed in TEAM version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Published: 2026-09-14
Score: 8.6 High
EPSS: < 1% Very Low
KEV: No
Impact: Privilege Escalation
Action: Immediate Patch
AI Analysis

Impact

The vulnerability involves incorrect privilege assignment in the Temporary Elevated Access Management (TEAM) component of AWS IAM Identity Center. An authenticated remote user with application-level access can read, approve, modify, or revoke any access request, thereby gaining unintended temporary elevated permissions in the AWS accounts managed by TEAM. The weakness is a CWE‑266 flaw, allowing an authorized user to alter privilege levels beyond intended scopes.

Affected Systems

The issue affects the AWS IAM Identity Center TEAM solution prior to version 1.5.1. All releases before v1.5.1 are vulnerable. The affected product is specified by the CNA as AWS:iam-identity-center-team.

Risk and Exploitability

The CVSS score of 8.6 indicates high severity. The EPSS score of <1% suggests a low but not zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated remote user with application-level access, requiring no additional network or device compromise. Because the flaw permits arbitrary modification or revocation of access requests, an attacker could gain unauthorized data access or full control of targeted AWS accounts.

Generated by OpenCVE AI on September 20, 2026 at 23:27 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade the IAM Identity Center TEAM component to version 1.5.1 or later, which includes the fix for privilege assignment.
  • If any forked or derivative code is in use, ensure it incorporates the same patch and update to the latest changes.
  • Audit existing application-level access permissions to confirm that only essential users have rights to manage access requests.

Generated by OpenCVE AI on September 20, 2026 at 23:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment. This issue has been addressed in TEAM version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Title Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center
First Time appeared Aws
Aws iam-identity-center-team
Weaknesses CWE-266
CPEs cpe:2.3:a:aws:iam-identity-center-team:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws iam-identity-center-team
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Aws Iam-identity-center-team
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-14T19:22:59.051Z

Reserved: 2026-09-08T14:28:43.921Z

Link: CVE-2026-86830

cve-icon Vulnrichment

Updated: 2026-09-14T19:14:56.906Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T19:17:52.523

Modified: 2026-09-14T20:59:31.310

Link: CVE-2026-86830

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-09-20T23:30:07Z

Weaknesses
  • CWE-266

    Incorrect Privilege Assignment