Impact
The vulnerability involves incorrect privilege assignment in the Temporary Elevated Access Management (TEAM) component of AWS IAM Identity Center. An authenticated remote user with application-level access can read, approve, modify, or revoke any access request, thereby gaining unintended temporary elevated permissions in the AWS accounts managed by TEAM. The weakness is a CWE‑266 flaw, allowing an authorized user to alter privilege levels beyond intended scopes.
Affected Systems
The issue affects the AWS IAM Identity Center TEAM solution prior to version 1.5.1. All releases before v1.5.1 are vulnerable. The affected product is specified by the CNA as AWS:iam-identity-center-team.
Risk and Exploitability
The CVSS score of 8.6 indicates high severity. The EPSS score of <1% suggests a low but not zero likelihood of exploitation, and the vulnerability is not listed in the CISA KEV catalog. The likely attack vector is an authenticated remote user with application-level access, requiring no additional network or device compromise. Because the flaw permits arbitrary modification or revocation of access requests, an attacker could gain unauthorized data access or full control of targeted AWS accounts.
OpenCVE Enrichment