CVE-2026-86516
MEDIUM
NVD
CVSS Score
4.7
Severity
MEDIUM
Published
Sep 08, 2026
Vendor
unknown
Description
A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is possible to initiate the attack remotely. The patch is named 6ab3147282d867c1993f995272750db091c2290b. Applying a patch is the recommended action to fix this issue.
References
- https://github.com/elenavanengelenmaslova/mocknest-serverless/
- https://github.com/elenavanengelenmaslova/mocknest-serverless/commit/6ab3147282d867c1993f995272750db091c2290b
- https://github.com/elenavanengelenmaslova/mocknest-serverless/pull/254
- https://vuldb.com/cve/CVE-2026-86516
- https://vuldb.com/submit/908568