Skip to main content

1Password actor granted themselves group or vault access

ID:1password_self_privilege_escalation
Data type:1Password
Severity:
Low
MITRE ATT&CK:TA0004:T1078

Description

AlphaSOC detected a 1Password actor granting themselves group membership, a group role, or access to a vault. Self-targeted access changes can bypass the review normally applied when privileges are granted to another user and may indicate an attempt to expand access to stored secrets.

Impact

An unauthorized privilege change can allow an attacker using a compromised account to access additional vaults, passwords, API keys, and other sensitive items. The attacker may then use those secrets to access other systems or retain access after the original compromise is discovered.

Severity

SeverityCondition
Low
Actor granted themselves group membership or vault access

Investigation and Remediation

Review the audit event to determine the acting user, the affected group or vault, and the access level granted. Confirm that the self-assignment was authorized. If not, remove the added membership, role, or vault permission; review the account's recent activity; and rotate any secrets the account could have accessed.