CVE-2026-82861: @hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass

Published Aug 31, 2026
·
Updated

@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass security policy checks by providing falsified evidence, causing the validator to miss unsafe bucket configurations.

Affected Software

1 affected component
npm/@hulumi/policies<1.3.2

Remediation

Recommended actions to resolve this vulnerability, in priority order.

  1. Upgrade

    Upgrade @hulumi/policies to a version that resolves this vulnerability.

    Fixed in 1.3.2
  2. Compensating control

    Until @hulumi/policies is upgraded to 1.3.2 or later, restrict access to policy evaluation inputs so attackers cannot submit spoofed SecureBucket parent evidence during policy evaluation.

Event History

Aug 31, 2026
CVE Published
via MITRE·08:46 AM
Data Sourced
via MITRE·08:46 AM
DescriptionSeverityWeakness

Frequently Asked Questions

1

Who can exploit this issue?

An attacker who can submit SecureBucket parent evidence to the policy evaluation process can provide spoofed evidence and bypass the affected security policy checks. No authentication or user interaction is required according to the supplied vector.

2

What configurations are at risk?

Unsafe bucket configurations are at risk when @hulumi/policies evaluates them using attacker-controlled or untrusted SecureBucket parent evidence. The provided information does not establish whether this condition exists in a default deployment.

3

What should teams do to remediate it?

Upgrade @hulumi/policies to version 1.3.2 or later. If upgrading cannot happen immediately, avoid accepting untrusted SecureBucket parent evidence in policy evaluation.

4

How can teams determine whether they are affected?

Identify deployments using the npm package @hulumi/policies at a version earlier than 1.3.2, then review whether their policy evaluation accepts or processes externally supplied SecureBucket parent evidence.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203