CVE-2026-86830 - Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center
Bulletin ID: 2026-112-AWS
Scope: AWS
Content Type: Important (requires attention)
Publication Date: 09/14/2026 10:45 AM PDT
Description:
Temporary Elevated Access Management (TEAM) is an open source AWS sample solution for managing temporary elevated access via AWS IAM Identity Center. We identified CVE-2026-86830, where an authenticated user with application-level access could gain unintended temporary elevated access to AWS accounts managed by TEAM.
Impacted versions: <1.5.1
Resolution:
This issue has been addressed in TEAM version 1.5.1. We recommend upgrading to the latest version and ensuring any forked or derivative code is patched to incorporate the new fixes.
Workarounds:
None.
References:
Acknowledgement:
We would like to thank Jani Muuriaisniemi at CUJO AI for collaborating on this issue through the coordinated vulnerability disclosure process.
Please email aws-security@amazon.com with any security questions or concerns.