CVE-2026-82859
9.8kerberosmansour · hulumi
A deployment SCP template vulnerability in hulumi versions before v1.3.2 allows attackers to bypass IAM boundary protections during tag-on-create operations.
Executive summary
The hulumi deployment tool contains a critical access control vulnerability that allows unauthenticated attackers to bypass IAM boundary restrictions, potentially leading to unauthorized privilege escalation.
Vulnerability
This vulnerability is categorized as an improper access control flaw (CWE-284) located within the deployment SCP template. It permits an unauthenticated attacker to circumvent intended IAM role protections during resource creation.
Business impact
The exploitation of this vulnerability poses a severe risk to organizational cloud security, as it allows attackers to override security boundaries established by Infrastructure as Code (IaC) roles. With a CVSS score of 9.8, this flaw represents a critical threat that could lead to unauthorized administrative access, data exfiltration, or complete takeover of downstream cloud resources.
Remediation
Immediate Action: Upgrade the kerberosmansour hulumi package to version 1.3.2 or later immediately to apply the secure SCP template.
Proactive Monitoring: Review IAM policy change logs and cloud audit trails for anomalous tag-on-create events or unauthorized modifications to sensitive infrastructure roles.
Compensating Controls: Implement strict Service Control Policies (SCPs) at the organization level to restrict resource creation permissions, effectively limiting the impact of the hulumi template bypass.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the critical CVSS severity of 9.8 and the fundamental nature of the IAM bypass, this vulnerability demands immediate attention from DevOps and security teams. Administrators should prioritize the update to version 1.3.2 across all environments to ensure that IaC role protections are correctly enforced. Failure to patch this vulnerability leaves the underlying cloud infrastructure susceptible to significant privilege escalation and unauthorized configuration changes.
More kerberosmansour CVEs
Sources
- GitHub Security Advisory (GHSA-86q4-r5j3-ff5c) Vendor advisory
- VulnCheck Advisory: hulumi before v1.3.2 SCP Template Tag-on-Create Bypass Third-party advisory