SNS topic policy has a wildcard or missing principal

Define the principals and actions in an SNS topic policy and review service-integration conditions to restrict unwanted publishing and access.

Description

In an SNS topic policy, Principal: "*" does not limit access to a specific account or role. Granting actions more broadly than necessary without suitable conditions can let untrusted principals publish messages or perform other allowed operations. Effective access depends on the actions, topic, conditions, and other applicable policies.

An access-grant statement in a topic policy needs a valid Principal and Effect: Allow. Omitting the principal from an allow statement is not a valid way to restrict access, and the omission itself does not grant access either.

Account-related conditions have different meanings. aws:ResourceAccount identifies the target resource's owner; it does not restrict the caller's account. aws:SourceAccount constrains the source resource's account in supported AWS service-to-service requests, rather than restricting every caller's account generally.

Potential impact

  • If sns:Publish is effectively granted to principals that do not need it, unwanted messages can be published to the topic.
  • When subscribers or automation receive those messages, they may generate misleading alerts, processing errors, or additional costs.
  • Effective cross-account permissions that exceed requirements can allow access beyond the intended trust boundary. The impact depends on actual actions, resources, and request conditions.

Remediation

  • Specify required AWS accounts, roles, or services using valid Principal syntax, and remove unnecessary allow statements.
  • Specify only required actions, such as sns:Publish, and exact topic ARNs. For service integrations, use conditions such as aws:SourceArn and aws:SourceAccount where the service supports them, and validate their operators and actual values.
  • Review the complete policy and associated Topics, and test requests that should be allowed and requests that should be denied. Confirm that required publishers and service integrations continue to work.

Topic policy configuration examples

These excerpts compare principal specifications. Both omit the required Topics property and use the incomplete ARN arn:aws:sns:MyTopic, which has no Region or account ID. They are not templates ready for deployment.

Publishing grant to a wildcard principal

yaml
AWSTemplateFormatVersion: '2010-09-09'
Description: ''
Resources:
  snsPolicy:
    Type: AWS::SNS::TopicPolicy
    Properties:
      PolicyDocument:
        Statement:
          - Sid: MyTopicPolicy
            Effect: Allow
            Principal: "*"
            Action:
              - sns:Publish
            Resource: arn:aws:sns:MyTopic

This statement intends to allow sns:Publish without limiting it to particular principals or conditions. When supplying the missing deployment properties, also restrict the grant to the required publishers and topic.

Incomplete principal specification

yaml
AWSTemplateFormatVersion: '2010-09-09'
Description: ''
Resources:
  snsPolicy:
    Type: AWS::SNS::TopicPolicy
    Properties:
      PolicyDocument:
        Statement:
          - Sid: MyTopicPolicy
            Effect: Allow
            Principal: "otherPrincipal"
            Action:
              - sns:Publish
            Resource: arn:aws:sns:MyTopic

otherPrincipal is not a valid AWS account or role identity. Replace it with a valid principal specification for the intended account, role, or service, complete the topic ARN and Topics, and validate the entire policy.

References