Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment.



This issue has been addressed in TEAM version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.

Project Subscriptions

Vendors Products
Iam-identity-center-team Subscribe
Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 14 Sep 2026 21:00:00 +0000

Type Values Removed Values Added
Description Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment. This issue has been addressed in TEAM version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Title Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center
First Time appeared Aws
Aws iam-identity-center-team
Weaknesses CWE-266
CPEs cpe:2.3:a:aws:iam-identity-center-team:*:*:*:*:*:*:*:*
Vendors & Products Aws
Aws iam-identity-center-team
References
Metrics cvssV3_1

{'score': 7.2, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.6, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-09-14T19:22:59.051Z

Reserved: 2026-09-08T14:28:43.921Z

Link: CVE-2026-86830

cve-icon Vulnrichment

Updated: 2026-09-14T19:14:56.906Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-09-14T19:17:52.523

Modified: 2026-09-14T20:59:31.310

Link: CVE-2026-86830

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses