CVE-2026-86516: elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges management
A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is possible to initiate the attack remotely. The patch is named 6ab3147282d867c1993f995272750db091c2290b. Applying a patch is the recommended action to fix this issue.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AWS GitHub OIDC Deployment Helper Script (github-oidc-role.yaml)to a version that resolves this vulnerability.Fixed in 0.9.0Patch 6ab3147282d867c1993f995272750db091c2290b - Compensating control
Since the issue is remotely exploitable and involves improper privilege management in the AWS GitHub OIDC Deployment Helper Script (file deployment/aws/shared/github-oidc-role.yaml), restrict access to the relevant AWS IAM role/credentials assumed via GitHub OIDC to only the minimum required principals (e.g., restrict the trusted OIDC subject/claims and limit who can use the role) until the patch is applied.
Event History
Frequently Asked Questions
Which component should be reviewed for exposure?
Review deployments that use the AWS GitHub OIDC Deployment Helper Script and its deployment/aws/shared/github-oidc-role.yaml file in mocknest-serverless 0.9.0.
What level of access does an attacker need?
The supplied severity vector indicates high privileges are required. The attack can be initiated remotely and does not require user interaction.
What is the recommended remediation?
Apply patch 6ab3147282d867c1993f995272750db091c2290b. The available data identifies this patch as the recommended fix for the improper privilege-management issue.