CVE-2026-82859: hulumi before v1.3.2 SCP Template Tag-on-Create Bypass
hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
hulumito a version that resolves this vulnerability.Fixed in 1.3.2
Event History
Frequently Asked Questions
Which deployments are exposed?
Downstream deployments using a Hulumi deployment SCP template from a version before 1.3.2 are exposed if they rely on hulumi:iac-role protections as an IAM boundary.
What does an attacker need to exploit this issue?
The issue is described as a tag-on-create bypass in the weakened SCP template. The provided data does not identify any required privileges, user interaction, or additional preconditions.
What is the remediation?
Use Hulumi version 1.3.2 or later so deployments receive the corrected SCP template. Existing downstream deployments should also be reviewed because the issue affects the deployed template.