PT-2026-48479 · Npm+2 · @Hulumi/Baseline+1
CVE-2026-48037
·
Published
2026-06-10
·
Updated
2026-07-27
CVSS v4.0
6.3
Medium
| Vector | AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:N/SC:L/SI:H/SA:N |
Name of the Vulnerable Software and Affected Versions
@hulumi/baseline versions prior to 1.4.0
Description
In the
AccountFoundation component, reuse paths for AWS detective services can lead to a downgraded security posture. When reusing GuardDuty, the system fails to verify if the existing detector is enabled or configured with the correct publishing cadence, potentially reporting success while the service remains suspended or misconfigured. Regarding Security Hub, the system creates CIS and NIST StandardsSubscription resources with default delete behavior. Consequently, destroying a stack triggers BatchDisableStandards, which unsubscribes the account from compliance monitoring, even if those subscriptions existed before the software was used.Recommendations
Update @hulumi/baseline to version 1.4.0.
As a temporary workaround, avoid reusing pre-existing detective services with
AccountFoundation or manually verify the detector posture.Exploit
Fix
Protection Mechanism Failure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Hulumi/Baseline
Hulumi