AWS Security ChangesHomeSearch

AWS AWSEC2: Clarified IAM permissions requirements

Service: AWSEC2 · 2026-08-16 · Documentation medium

File: AWSEC2/latest/UserGuide/permissions-for-launch-templates.md · Type: iam

Summary

Specified 'launch template user' must have permissions for AMI launch and EBS operations

Security assessment

Explicitly documents IAM permission requirements to prevent privilege escalation risks and unauthorized resource access

Evidence

  * To create EBS volumes with tags from existing snapshots, the launch template user must have read access to the snapshots, and permissions to create and tag volumes.

Diff

diff --git a/AWSEC2/latest/UserGuide/permissions-for-launch-templates.md b/AWSEC2/latest/UserGuide/permissions-for-launch-templates.md
index 8617fc90e..412a8a633 100644
--- a//AWSEC2/latest/UserGuide/permissions-for-launch-templates.md
+++ b//AWSEC2/latest/UserGuide/permissions-for-launch-templates.md
@@ -19 +19 @@ You must grant anyone that will use a launch template the permissions required t
-  * To launch an instance from a shared private Amazon Machine Image (AMI), the user must have launch permission for the AMI.
+  * To launch an instance from a shared private Amazon Machine Image (AMI), the launch template user must have launch permission for the AMI.
@@ -21 +21 @@ You must grant anyone that will use a launch template the permissions required t
-  * To create EBS volumes with tags from existing snapshots, the user must have read access to the snapshots, and permissions to create and tag volumes.
+  * To create EBS volumes with tags from existing snapshots, the launch template user must have read access to the snapshots, and permissions to create and tag volumes.