CVE-2026-86830: Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center
Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center solution before version 1.5.1 might allow an authenticated remote user with application-level access to read, approve, modify, or revoke arbitrary access requests, thereby obtaining unintended temporary elevated access to the AWS accounts accessed using the TEAM deployment.
This issue has been addressed in TEAM version 1.5.1 or later. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
AWS IAM Identity Center TEAMto a version that resolves this vulnerability.Fixed in 1.5.1
Event History
Frequently Asked Questions
Who can exploit this issue?
An authenticated remote user who already has application-level access to the TEAM deployment may exploit it. The issue affects TEAM versions before 1.5.1.
What could an attacker do with this vulnerability?
They may be able to read, approve, modify, or revoke arbitrary access requests. This could allow them to obtain unintended temporary elevated access to AWS accounts accessed through the TEAM deployment.
What remediation is available?
Upgrade TEAM to version 1.5.1 or later, preferably the latest version. Forked or derivative TEAM code should also be patched to incorporate the fixes.