CVE-2026-86516
MEDIUMCVSS 4.7Description
A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is possible to initiate the attack remotely. The patch is named 6ab3147282d867c1993f995272750db091c2290b. Applying a patch is the recommended action to fix this issue.
Timeline
Published:September 8th, 2026 4:17 AM
Last modified:September 8th, 2026 4:17 AM
CVSS Scoring
CVSS v3: 4.7 (MEDIUM)
CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:L/A:L
CVSS v2: 5.8
References & Reports
Advisories, patches, and third-party reports
- https://github.com/elenavanengelenmaslova/mocknest-serverless/
- https://github.com/elenavanengelenmaslova/mocknest-serverless/commit/6ab3147282d867c1993f995272750db091c2290b
- https://github.com/elenavanengelenmaslova/mocknest-serverless/pull/254
- https://vuldb.com/cve/CVE-2026-86516
- https://vuldb.com/submit/908568
- https://vuldb.com/vuln/399670
- https://vuldb.com/vuln/399670/cti
Source: NIST NVD · Data may lag official sources by up to one minute