CVE-2026-86516 Details
Description
A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is possible to initiate the attack remotely. The patch is named 6ab3147282d867c1993f995272750db091c2290b. Applying a patch is the recommended action to fix this issue.
A vulnerability exists in MockNest Serverless version 0.9.0, specifically within the AWS GitHub OIDC Deployment Helper Script. The issue arises from improper privilege management in the GitHub Actions OIDC role configuration, allowing for overly permissive access. This vulnerability can be exploited remotely by manipulating the OIDC role settings, which are managed through a CloudFormation template deployed via GitHub Actions.
To address this vulnerability, the GitHub Actions OIDC role should be updated to a more secure configuration. This involves deploying a revised CloudFormation template that restricts the role's permissions and ensures it only trusts the main branch of the repository. Instructions for updating the OIDC role can be found in the MockNest Serverless repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Sep 8, 2026CISA-ADP
Assessed Sep 8, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/elenavanengelenmaslova/mocknest-serverless/ | [email protected] | ProductVendor |
| https://github.com/elenavanengelenmaslova/mocknest-serverless/commit/6ab3147282d867c1993f995272750db091c2290b | [email protected] | Source CodeVendor |
| https://github.com/elenavanengelenmaslova/mocknest-serverless/pull/254 | [email protected] | Issue TrackingVendor |
| https://vuldb.com/cve/CVE-2026-86516 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/submit/908568 | [email protected] | Issue TrackingPermission Required |
| https://vuldb.com/vuln/399670 | [email protected] | AdvisoryPermission Required |
| https://vuldb.com/vuln/399670/cti | [email protected] | Content Wall |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-266 | Incorrect Privilege Assignment | [email protected] |
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| elenavanengelenmaslova mocknest-serverless | 0.9.0 (semver) |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Sep 23, 2026 | CVE Translated | [email protected] |
| Sep 8, 2026 | CVE Modified | CISA-ADP |
| Sep 8, 2026 | New CVE Received | [email protected] |
Volerion