PT-2026-48476 · Npm+2 · @Hulumi/Policies+1

CVE-2026-48034

·

Published

2026-06-10

·

Updated

2026-07-24

CVSS v4.0

8.5

High

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:H/SI:H/SA:L
Name of the Vulnerable Software and Affected Versions @hulumi/policies versions prior to 1.4.0
Description A bypass exists in the H5 defense-in-depth check of the Hulumi hardening pack. The H5 check is designed to verify that raw aws:s3:Bucket resources acting as children of a SecureBucket component possess five mandatory hardening sibling resources: public-access block, SSE-KMS, ownership controls, versioning, and a TLS-only bucket policy. The issue occurs because the check only verified the types of these sibling resources without confirming they were actually applied to the specific bucket being exempted. An attacker or a compromised pull request could associate an unhardened raw bucket with five decoy sibling resources that point to a different bucket, causing the policy pack to incorrectly report the stack as compliant while the actual bucket remains unhardened.
Recommendations Upgrade to @hulumi/policies version 1.4.0.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48034
GHSA-9VC9-4JV3-RF86

Affected Products

@Hulumi/Policies
Hulumi