IAM user has excessive iam:CreateAccessKey permissions

Restrict permission to create access keys for other users.

Description

Broad iam:CreateAccessKey permission can allow the creation of new access keys for other IAM users and their use for API access. If a target user has stronger permissions, this can lead to privilege escalation.

Potential impact

  • New long-term keys can provide access to the target user’s data and services.
  • Unnecessary keys can preserve an access path after the original permissions are changed.

Remediation

Remove unnecessary iam:CreateAccessKey permission and limit required key administration to approved target users. Prefer temporary credentials where possible, and review key-creation events and existing long-term keys.

Examples

The second inline policy grants the same user only EC2 describe permissions. Check other policies for key-creation permissions and separately deactivate or delete keys already issued.

Before

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "test_inline_policy"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "iam:CreateAccessKey",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

After

hcl
resource "aws_iam_user" "example" {
  name = "cosmic"
}

resource "aws_iam_user_policy" "example" {
  name = "inline_policy_read_only"
  user = aws_iam_user.example.name

  policy = jsonencode({
    Version = "2012-10-17"
    Statement = [
      {
        Action = [
          "ec2:Describe*",
        ]
        Effect   = "Allow"
        Resource = "*"
      },
    ]
  })
}

References