AWS API Gateway not private

Updated: February 25, 2026

Description

Severity: Low

A private API Gateway is configured with an IAM policy that allows public access.

Remediation

Review and update the IAM policy attached to the API Gateway to ensure it restricts access appropriately.