PT-2026-48479 · Npm+2 · @Hulumi/Baseline+1

CVE-2026-48037

·

Published

2026-06-10

·

Updated

2026-07-27

CVSS v4.0

6.3

Medium

VectorAV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:H/SA:N
Name of the Vulnerable Software and Affected Versions @hulumi/baseline versions prior to 1.4.0
Description In the AccountFoundation component, reuse paths for AWS detective services can lead to a downgraded security posture. When reusing GuardDuty, the system fails to verify if the existing detector is enabled or configured with the correct publishing cadence, potentially reporting success while the service remains suspended or misconfigured. Regarding Security Hub, the system creates CIS and NIST StandardsSubscription resources with default delete behavior. Consequently, destroying a stack triggers BatchDisableStandards, which unsubscribes the account from compliance monitoring, even if those subscriptions existed before the software was used.
Recommendations Update @hulumi/baseline to version 1.4.0. As a temporary workaround, avoid reusing pre-existing detective services with AccountFoundation or manually verify the detector posture.

Exploit

Fix

Protection Mechanism Failure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-48037
GHSA-CJ8G-PRCM-MFG5

Affected Products

@Hulumi/Baseline
Hulumi