CVE-2026-82857: hulumi before v1.3.2 Privilege Escalation via IAM Policy

Published Aug 31, 2026
·
Updated

hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e- roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account.

Affected Software

1 affected component
hulumi<1.3.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade hulumi to a version that resolves this vulnerability.

    Fixed in 1.3.2
  2. Compensating control

    In the weekly integration IAM policy, prevent role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions (i.e., ensure appropriate permissions boundaries are enforced).

Event History

Aug 31, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Which deployments are exposed?

hulumi versions before 1.3.2 are affected where the weekly integration IAM policy is present and a principal has the documented access to use it. The impact described is in the sandbox account.

2

What access does an attacker need?

An attacker needs the documented principal permitted by the weekly integration IAM policy. They can then perform role lifecycle operations on af-e2e-* roles and create persistent higher-privilege roles.

3

How can I identify potentially affected roles?

Review the weekly integration IAM policy for permissions allowing role lifecycle operations on roles matching af-e2e-*. Check the sandbox account for persistent higher-privilege roles created under that naming pattern.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203