CVE-2026-86516: Elenavanengelenmaslova Mocknest-Serverless
Medium severity, CVSS 4.7. EPSS: 0.4% chance of exploitation in the next 30 days.
A vulnerability was detected in elenavanengelenmaslova mocknest-serverless 0.9.0. The affected element is an unknown function of the file deployment/aws/shared/github-oidc-role.yaml of the component AWS GitHub OIDC Deployment Helper Script. Performing a manipulation results in improper privilege management. It is possible to initiate the attack remotely. The patch is named 6ab3147282d867c1993f995272750db091c2290b. Applying a patch is the recommended action to fix this issue.
Affected products
- Elenavanengelenmaslova Mocknest-Serverless: version 0.9.0 only
Published 2026-09-08. Last modified 2026-09-23.