PT-2026-83736 · Hulumi · Hulumi
CVE-2026-82859
·
Published
2026-08-31
·
Updated
2026-08-31
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
hulumi versions prior to 1.3.2
Description
The software contains a deployment Service Control Policy (SCP) template that allows tag-on-create bypasses for
hulumi:iac-role protections. This issue enables attackers to bypass intended Identity and Access Management (IAM) boundary restrictions by exploiting the weakened SCP template in downstream deployments.Recommendations
Update hulumi to version 1.3.2 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Hulumi