PT-2026-83738 · Npm · @Hulumi/Policies

CVE-2026-82861

·

Published

2026-05-21

·

Updated

2026-09-02

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions @hulumi/policies versions prior to 1.3.2
Description An issue exists where attackers can submit spoofed SecureBucket parent evidence during policy evaluation. By providing falsified evidence, attackers can bypass security policy checks, which leads the validator to overlook unsafe bucket configurations.
Recommendations Upgrade @hulumi/policies to version 1.3.2 or later.

Exploit

Fix

Improper Access Control

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82861
GHSA-G43V-9X7Q-83PQ

Affected Products

@Hulumi/Policies