Sceawere

Vulnerability Detail

CVE-2026-86516UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Improper Privilege Management in mocknest-serverless

Vulnerability Metadata

Severity
Medium
Score / CVSS
4.7
Creation Date
2h ago
Vendor
elenavanengelenmaslova
Product
mocknest-serverless
Attack Type
Improper Privilege Management
Vector String
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
Attack Complexity
LOW

Narrative and Response

Description

A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is possible to initiate the attack remotely. The patch is named 6ab3147282d867c1993f995272750db091c2290b. Applying a patch is the recommended action to fix this issue.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "4.7",
  "pubDate": "2026-09-08T04:17:42.030Z",
  "pubdate": "2026-09-08T04:17:42.030Z",
  "executiveSummary": "A critical security vulnerability involving improper privilege management has been identified in the AWS GitHub OIDC Deployment Helper Script within the elenavanengelenmaslova mocknest-serverless project, version 0.9.0.\nThe vulnerability resides in the deployment/aws/shared/github-oidc-role.yaml configuration file and allows remote attackers to manipulate OIDC-based role assignments.\nBy exploiting the misconfiguration, an unauthorized actor could potentially elevate their privileges or gain unauthorized access to AWS resources protected by the OIDC role.\nThis flaw represents a significant risk to the integrity and confidentiality of the deployment environment, as it facilitates unauthorized administrative actions.\nRemote exploitation is possible, requiring no prior authentication within the target system, though it relies on the reachability of the OIDC configuration. Immediate remediation is required to prevent unauthorized infrastructure control.",
  "technicalDetails": "The vulnerability originates from improper privilege management within the AWS GitHub OIDC Deployment Helper Script, specifically located in the deployment/aws/shared/github-oidc-role.yaml file. This file defines the IAM role trust policy and permissions granted to the GitHub OIDC provider for automated deployments.\nThe root cause is a misconfigured or overly permissive trust policy or permission set that fails to adequately scope the identity or the actions granted to the OIDC provider. Because the configuration is used in a serverless deployment context, it directly affects the AWS environment's access control layer.\nThe attack flow commences with the remote identification of the OIDC deployment setup. An attacker can leverage the overly permissive configuration to assume or manipulate the identity associated with the GitHub OIDC role. By manipulating the parameters handled by the OIDC helper script, an attacker can trick the AWS STS (Security Token Service) into issuing credentials that exceed the intended scope of the service account.\nBecause the role is specifically designed to facilitate deployment, successful exploitation grants the attacker the permissions associated with the deployment pipeline. This often includes, but is not limited to, the ability to read, modify, or delete infrastructure-as-code (IaC) resources, update Lambda functions, or modify IAM policies within the AWS account.\nThe attack does not require direct access to the source code repository if the OIDC provider's trust relationship is configured to trust malicious or overly broad GitHub subject claims. The exploitation surface is exposed over the network via the AWS IAM service, which processes the OIDC token exchange initiated by the actor.\nPost-exploitation impact is severe, as it grants the attacker persistence within the cloud environment. The attacker may move laterally, exfiltrate sensitive environment variables, or execute arbitrary code in the context of the serverless function, effectively bypassing the principle of least privilege. The vulnerability is categorized as a failure in secure configuration management, specifically failing to constrain the OIDC trust relationship, allowing unauthorized privilege escalation through external identity providers."
}
CVE-2026-86516: Improper Privilege Management in mocknest-serverless (MEDIUM Severity, CVSS: 4.7) - Sceawere