PT-2026-91399 · Aws · Temporary Elevated Access Management

·

CVE-2026-86830

·

Published

2026-09-14

·

Updated

2026-09-16

CVSS v4.0

8.6

High

VectorAV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center versions prior to 1.5.1
Description An incorrect privilege assignment exists that may allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests. This authorization weakness can be used to manipulate the privileged-access workflow, enabling the user to obtain unintended temporary elevated access to the AWS accounts managed through the TEAM deployment.
Recommendations Upgrade Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center to version 1.5.1 or later. Ensure any forked or derivative code is patched to incorporate the new fixes.

Exploit

Fix

Incorrect Privilege Assignment

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-86830
GHSA-6X87-MJV8-MGVJ

Affected Products

Temporary Elevated Access Management