AWS Security ChangesHomeSearch

AWS managedservices: Fix SAML claim rule regex to match 12-digit account ID

Service: managedservices · 2026-09-27 · Documentation medium

File: managedservices/latest/userguide/adfs-claim-rule-saml.md · Type: authz

Summary

Corrected the ADFS claim rule regex from [^d]{12} to [\d]{12} in the condition and RegExReplace role ARN mapping.

Security assessment

Same SAML federation role-mapping regex correction ensuring only 12-digit account IDs map to IAM role ARNs. Authorization-relevant documentation fix, not tied to a specific CVE.

Evidence

+                        c:[Type == "http://temp/variable", Value =~ "(?i)^AWS-([\d]{12})-"]

Diff

diff --git a/managedservices/latest/userguide/adfs-claim-rule-saml.md b/managedservices/latest/userguide/adfs-claim-rule-saml.md
index 26781e1ba..33eb5d5e6 100644
--- a//managedservices/latest/userguide/adfs-claim-rule-saml.md
+++ b//managedservices/latest/userguide/adfs-claim-rule-saml.md
@@ -48 +48 @@ The relying party trust and claims rules steps are taken from [ Enabling Federat
-                        c:[Type == "http://temp/variable", Value =~ "(?i)^AWS-([^d]{12})-"]
+                        c:[Type == "http://temp/variable", Value =~ "(?i)^AWS-([\d]{12})-"]
@@ -51 +51 @@ The relying party trust and claims rules steps are taken from [ Enabling Federat
-                        => issue(Type = "https://aws.amazon.com/SAML/Attributes/Role", Value = RegExReplace(c.Value, "AWS-([^d]{12})-", "arn:aws:iam::$1:saml-provider/customer-readonly-saml,arn:aws:iam::$1:role/"));    
+                        => issue(Type = "https://aws.amazon.com/SAML/Attributes/Role", Value = RegExReplace(c.Value, "AWS-([\d]{12})-", "arn:aws:iam::$1:saml-provider/customer-readonly-saml,arn:aws:iam::$1:role/"));