Security Advisory Desk
unratedQCS priority 70/100Amazon Web Services

CVE-2026-86830 - Incorrect privilege assignment in Temporary Elevated Access Management (TEAM) for AWS IAM Identity Center

Temporary Elevated Access Management (TEAM) is an open source tool from AWS that helps manage temporary higher-level permissions using AWS IAM Identity Center. A security issue was found where a user who is allowed to use the application could gain more temporary access rights than intended to certain AWS accounts. This could let them perform actions they should not be allowed to do. AWS released version 1.5.1 of TEAM to fix this problem and recommends upgrading. There are no workarounds available, so updating is necessary to protect your environment.

Published 14/9/2026, 6:04:59 pmVerified 15/9/2026, 12:27:28 amRevision 1
Amazon Web Services unrated network security advisory visual

In plain language

What this advisory means

Temporary Elevated Access Management (TEAM) is an open source tool from AWS that helps manage temporary higher-level permissions using AWS IAM Identity Center. A security issue was found where a user who is allowed to use the application could gain more temporary access rights than intended to certain AWS accounts. This could let them perform actions they should not be allowed to do. AWS released version 1.5.1 of TEAM to fix this problem and recommends upgrading. There are no workarounds available, so updating is necessary to protect your environment.

Technical explanation

How the issue affects the environment

The vulnerability identified as CVE-2026-86830 occurs in the Temporary Elevated Access Management (TEAM) solution, which integrates with AWS IAM Identity Center to provide temporary elevated permissions. The flaw relates to incorrect privilege assignment logic, allowing an authenticated user with application-level access to escalate their temporary access privileges beyond intended scopes on AWS accounts managed by TEAM. This improper access control could lead to unauthorized privilege escalation within the affected AWS environment. The issue is addressed in TEAM version 1.5.1, which corrects the privilege assignment mechanism. There are no alternative mitigations; users must upgrade to remediate the vulnerability.

Operational impact

Why teams should care

If exploited, this vulnerability enables authenticated users to gain unintended temporary elevated access to AWS accounts managed via TEAM. This could lead to unauthorized administrative actions, increasing the risk of data breaches, service disruptions, or other malicious activities. Organizations using TEAM to manage elevated access could face compliance, operational, and reputational risks if the issue is not resolved promptly.

Immediate action

Upgrade TEAM to version 1.5.1 or later and ensure that all forked or derivative codebases are also patched accordingly to incorporate the corrected privilege assignment fixes.

Affected and fixed releases

Affected versionsVersions prior to 1.5.1 of Temporary Elevated Access Management (TEAM)
Fixed versions1.5.1

Temporary risk reduction

None specified by the AWS security bulletin. Immediate upgrade is recommended.

Evidence and validation checklist

  • AWS Security Bulletin ID 2026-112-AWS dated 09/14/2026
  • Official statement that authenticated users could gain unintended temporary elevated access
  • TEAM version 1.5.1 addresses the vulnerability
  • No workaround available
  • Acknowledgement of coordinated disclosure with CUJO AI

Authoritative reference

AWS Security Bulletins

QCS detected and normalized this record from the official source. Vendor guidance remains authoritative.

Open source