PT-2026-91399 · Aws · Temporary Elevated Access Management
CVSS v4.0
8.6
High
| Vector | AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center versions prior to 1.5.1
Description
An incorrect privilege assignment exists that may allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests. This authorization weakness can be used to manipulate the privileged-access workflow, enabling the user to obtain unintended temporary elevated access to the AWS accounts managed through the TEAM deployment.
Recommendations
Upgrade Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center to version 1.5.1 or later.
Ensure any forked or derivative code is patched to incorporate the new fixes.
Exploit
Fix
Incorrect Privilege Assignment
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Temporary Elevated Access Management