CVE-2026-82857: hulumi before v1.3.2 Privilege Escalation via IAM Policy
hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e- roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
hulumito a version that resolves this vulnerability.Fixed in 1.3.2 - Compensating control
In the weekly integration IAM policy, prevent role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions (i.e., ensure appropriate permissions boundaries are enforced).
Event History
Frequently Asked Questions
Which deployments are exposed?
hulumi versions before 1.3.2 are affected where the weekly integration IAM policy is present and a principal has the documented access to use it. The impact described is in the sandbox account.
What access does an attacker need?
An attacker needs the documented principal permitted by the weekly integration IAM policy. They can then perform role lifecycle operations on af-e2e-* roles and create persistent higher-privilege roles.
How can I identify potentially affected roles?
Review the weekly integration IAM policy for permissions allowing role lifecycle operations on roles matching af-e2e-*. Check the sandbox account for persistent higher-privilege roles created under that naming pattern.