PT-2026-83738 · Npm · @Hulumi/Policies
CVE-2026-82861
·
Published
2026-05-21
·
Updated
2026-09-02
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
@hulumi/policies versions prior to 1.3.2
Description
An issue exists where attackers can submit spoofed SecureBucket parent evidence during policy evaluation. By providing falsified evidence, attackers can bypass security policy checks, which leads the validator to overlook unsafe bucket configurations.
Recommendations
Upgrade @hulumi/policies to version 1.3.2 or later.
Exploit
Fix
Improper Access Control
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
@Hulumi/Policies