{"id":"CVE-2026-86516","summary":"elenavanengelenmaslova mocknest-serverless AWS GitHub OIDC Deployment Helper Script github-oidc-role.yaml privileges management","details":"A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is possible to initiate the attack remotely. The patch is named 6ab3147282d867c1993f995272750db091c2290b. Applying a patch is the recommended action to fix this issue.","modified":"2026-09-09T03:48:17.453729980Z","published":"2026-09-08T03:15:09.819Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86516.json","cna_assigner":"VulDB","cwe_ids":["CWE-266","CWE-269"]},"references":[{"type":"WEB","url":"https://github.com/elenavanengelenmaslova/mocknest-serverless/"},{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/86xxx/CVE-2026-86516.json"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-86516"},{"type":"ADVISORY","url":"https://vuldb.com/cve/CVE-2026-86516"},{"type":"ADVISORY","url":"https://vuldb.com/submit/908568"},{"type":"ADVISORY","url":"https://vuldb.com/vuln/399670"},{"type":"REPORT","url":"https://vuldb.com/vuln/399670/cti"},{"type":"FIX","url":"https://github.com/elenavanengelenmaslova/mocknest-serverless/commit/6ab3147282d867c1993f995272750db091c2290b"},{"type":"FIX","url":"https://github.com/elenavanengelenmaslova/mocknest-serverless/pull/254"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/elenavanengelenmaslova/mocknest-serverless","events":[{"introduced":"537dae82c8e27946e26f19496e0ad99ceadccf27"},{"fixed":"6ab3147282d867c1993f995272750db091c2290b"}],"database_specific":{"extracted_events":[{"introduced":"0.9.0"},{"last_affected":"0.9.0"}],"source":["AFFECTED_FIELD","REFERENCES"]}}],"versions":["0.9.0"],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-86516.json"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:L/VI:L/VA:L/SC:N/SI:N/SA:N/E:X"}]}