CVE-2026-86516
Severity CVSS v4.0:
MEDIUM
Type:
Unavailable / Other
Publication date:
08/09/2026
Last modified:
23/09/2026
Description
A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is possible to initiate the attack remotely. The patch is named 6ab3147282d867c1993f995272750db091c2290b. Applying a patch is the recommended action to fix this issue.
Impact
Base Score 4.0
5.10
Severity 4.0
MEDIUM
Base Score 3.x
4.70
Severity 3.x
MEDIUM
Base Score 2.0
5.80
Severity 2.0
MEDIUM
References to Advisories, Solutions, and Tools
- https://github.com/elenavanengelenmaslova/mocknest-serverless/
- https://github.com/elenavanengelenmaslova/mocknest-serverless/commit/6ab3147282d867c1993f995272750db091c2290b
- https://github.com/elenavanengelenmaslova/mocknest-serverless/pull/254
- https://vuldb.com/cve/CVE-2026-86516
- https://vuldb.com/submit/908568
- https://vuldb.com/vuln/399670
- https://vuldb.com/vuln/399670/cti


