Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM...
UnratedCVE-2026-86830 · Published Sep 14, 2026
Bulletin ID: 2026-112-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 09/14/2026 10:45 AM PDT Description: Temporary Elevated Access Management (TEAM) is an open source AWS sample solution for managing temporary elevated access via AWS IAM Identity Center. We identified CVE-2026-86830, where an authenticated user with application-level access could gain unintended temporary elevated access to AWS accounts managed by TEAM. Impacted versions: <1.5.1 Please refer to the article below for the most up-to-date and complete information related to this AWS Security Bulletin.
Affected versions
Details and references
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 17 | Improper validation of certificate with host mismatch in AWS IoT Device SDK for Python | Unrated | No fix yet |
| Sep 16 | Improper validation of pod identifier uniqueness in aws-network-policy-agent in Amazon EKS | Unrated | No fix yet |
| Sep 11 | Kiro IDE Sensitive Workspace Data Exfiltration via Agent-Written Workspace Configuration | Unrated | No fix yet |
| Sep 11 | Denial of service in the event stream header decoder in AWS SDK for Go v2 | Unrated | No fix yet |
| Sep 11 | XML External Entity (XXE) in AWS Advanced JDBC Wrapper RemoteQueryCachePlugin | Unrated | No fix yet |
| Sep 11 | Issue with projen - Path traversal and OS command injection | Unrated | No fix yet |