Description
Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment.



This issue has been addressed in TEAM version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Published: 2026-09-14
Score: 8.6 High
EPSS: n/a
KEV: No
AI Analysis

Analysis and contextual insights are available on OpenCVE Cloud.

Remediation

No vendor fix or workaround currently provided.

Additional remediation guidance may be available on OpenCVE Cloud.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment. This issue has been addressed in TEAM version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Title Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center
First Time appeared Aws
Aws iam-identity-center-team
Weaknesses CWE-266
CPEs cpe:2.3:a:aws:iam-identity-center-team:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws iam-identity-center-team
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Subscriptions

Aws Iam-identity-center-team
cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-14T19:22:59.051Z

Reserved: 2026-09-08T14:28:43.921Z

Link: CVE-2026-86830

cve-icon Vulnrichment

Updated: 2026-09-14T19:14:56.906Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T19:17:52.523

Modified: 2026-09-14T20:59:31.310

Link: CVE-2026-86830

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses