PT-2026-83740 · Npm · @Hulumi/Baseline

CVE-2026-82863

·

Published

2026-05-21

·

Updated

2026-09-01

CVSS v4.0

6.9

Medium

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N
Name of the Vulnerable Software and Affected Versions @hulumi/baseline versions prior to 1.3.2
Description Failure to fully detect CloudTrail selector tampering events reduces the coverage of audit logging configuration changes. This allows attackers to modify CloudTrail event selectors without complete detection, potentially enabling them to evade audit trail monitoring.
Recommendations Upgrade @hulumi/baseline to version 1.3.2 or later and rerun affected previews or checks.

Exploit

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82863
GHSA-GFP8-MP24-5VXG

Affected Products

@Hulumi/Baseline