PT-2026-83737 · Npm · @Hulumi/Policies

CVE-2026-82860

·

Published

2026-05-21

·

Updated

2026-08-31

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions @hulumi/policies versions prior to 1.3.2
Description Failure to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail allows attackers to craft admin-equivalent policy paths that bypass policy evaluation controls.
Recommendations Upgrade @hulumi/policies to version 1.3.2 or later.

Exploit

Fix

Improper Privilege Management

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82860
GHSA-4XRH-5M3M-328W

Affected Products

@Hulumi/Policies