The Amazon Web Services (AWS) Security Team has issued an authoritative security advisory addressing CVE-2026-46210 (CVSS 9.1), a critical authorization bypass defect in AWS IAM Identity Center (formerly AWS Single Sign-On). The vulnerability allowed an authenticated administrator of a federated identity provider (IdP) to forge cross-tenant group synchronization claims, escalating unassigned permissions within connected AWS Organizations member accounts.

Root Cause: SCIM Attribute Mapping Flaw (CWE-287 / CWE-863)

Enterprises synchronize user directories between third-party identity platforms (such as Okta, PingFederate, or Microsoft Entra ID) and AWS IAM Identity Center using the System for Cross-domain Identity Management (SCIM) v2.0 protocol. The synchronization daemon accepts JSON payloads over HTTPS to automatically provision users, assign group memberships, and bind IAM permission sets.

AWS's internal audit identified that when parsing SCIM PATCH requests targeting group membership structures, the backend validator failed to enforce tenant boundary checks against internal account identifier headers:

// Vulnerable SCIM PATCH group membership handler logic
POST /scim/v2/Groups/1a2b3c/members HTTP/1.1
Host: identitycenter.us-east-1.amazonaws.com
Authorization: Bearer scim_token_live_...

{
  "schemas": ["urn:ietf:params:scim:api:messages:2.0:PatchOp"],
  "Operations": [{
    "op": "add",
    "path": "members",
    "value": [{"value": "usr-98765", "targetTenant": "aws-org-foreign-id"}]
  }]
}

Because the targetTenant parameter was processed before tenancy verification completed, an adversary with SCIM provisioning credentials in one tenant could bind their identity into high-privilege administrator groups belonging to adjacent organization partitions.

Threat Modeling and Cloud Blast Radius

Successful exploitation granted the adversary administrative access across target multi-account AWS environments:

  • Permission Set Escalation: Attackers added federated identities to the AWSAdministratorAccess group, bypassing least-privilege IAM guardrails and gaining full control over S3 storage, EC2 workloads, and KMS cryptographic keys.
  • Silent Persistence: Malicious group bindings persisted within the internal AWS Identity Center cache even if the upstream IdP account was disabled, creating an undetected backdoor.
  • Organization Boundary Breach: Federated roles could assume cross-account access into sensitive production workloads across global AWS regions.

Remediation and Defensive Verification

AWS deployed an automated server-side patch across all AWS regions. Enterprise cloud security architects should implement the following validation playbook:

Defensive Step Recommended Action Tool / Query
Token Regeneration Rotate all inbound SCIM endpoint access tokens. AWS Management Console > IAM Identity Center > Settings > Identity source
CloudTrail Audit Inspect CloudTrail events for sso-directory:AddMemberToGroup. aws cloudtrail lookup-events --lookup-attributes AttributeKey=EventName,AttributeValue=AddMemberToGroup
SCP Boundary Enforce Deploy Service Control Policies (SCPs) preventing IAM role tampering. Enforce aws:PrincipalOrgID matching condition across all IAM policies.