Executive brief
Temporary Elevated Access Management (TEAM) is an AWS sample solution for securely granting temporary elevated permissions to AWS accounts via IAM Identity Center. A vulnerability in TEAM versions before 1.5.1 allows authenticated users with basic application access to obtain unintended elevated privileges, potentially granting attackers access to sensitive AWS resources and accounts they should not be able to access.
Technical details
CVE-2026-86830 is an incorrect privilege assignment vulnerability in AWS TEAM (Temporary Elevated Access Management), an open-source sample solution for managing temporary elevated access through AWS IAM Identity Center. An authenticated user with application-level access can exploit this flaw to gain unintended temporary elevated access to AWS accounts managed by TEAM. The vulnerability stems from improper privilege assignment logic that fails to properly restrict elevation scope or duration. The attack requires valid authentication to the TEAM application but does not require administrative access initially. Exploitation allows an attacker to escalate from standard user permissions to elevated account access, potentially enabling unauthorized cloud resource access or modification. Fixed versions 1.5.1 and later are available.
Affected products
- AWS Temporary Elevated Access Management (TEAM) <1.5.1
Timeline
- 2026-09-14: disclosed