CVE-2026-82857

9.8

kerberosmansour · hulumi

A privilege escalation vulnerability in the hulumi IAM policy allows unauthenticated attackers to create persistent higher-privilege roles in the sandbox account.

Executive summary

A critical privilege escalation vulnerability in kerberosmansour hulumi allows unauthenticated attackers to compromise sandbox accounts by creating unauthorized high-privilege roles.

Vulnerability

This vulnerability, classified as CWE-269, arises from improper privilege management within the weekly integration IAM policy. The flaw allows unauthenticated remote attackers to perform role lifecycle operations on specified roles without boundary restrictions, facilitating the creation of persistent, elevated-privilege roles.

Business impact

The ability for an unauthenticated actor to manipulate IAM roles poses a severe risk to cloud infrastructure integrity. Successful exploitation could lead to full administrative compromise of the sandbox environment, unauthorized data access, and the persistence of malicious backdoors. Given the CVSS score of 9.8, this vulnerability represents an immediate threat to business operations and security posture.

Remediation

Immediate Action: Upgrade the kerberosmansour hulumi package to version 1.3.2 or later to apply the necessary IAM policy boundary restrictions.

Proactive Monitoring: Review IAM access logs for unauthorized role creation events and monitor for unexpected changes to role policies within the sandbox account.

Compensating Controls: Restrict network access to the management interface and enforce strict IAM boundary policies that prevent the creation of roles with permissions exceeding the sandbox scope.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

The critical nature of this vulnerability, combined with the lack of required authentication for exploitation, necessitates an immediate response. Security teams must prioritize patching the hulumi software to version 1.3.2 across all environments. Failure to remediate could allow attackers to gain long-term, elevated access to cloud resources.

More kerberosmansour CVEs

Sources