← Back to overview

The npm package @hulumi/policies versions before 1.3.2 contains a vulnerability where inline and attached IAM policy evidence is not fully inspected for the administrator-policy guardrail. This flaw allows attackers to craft admin-equivalent policy paths that bypass policy evaluation controls. The vulnerability effectively enables privilege escalation by circumventing intended access restrictions. Users should upgrade to version 1.3.2 or later to remediate the issue. The vulnerability has been assigned CVE-2026-82860 and is rated high severity. It poses a significant risk in cloud environments where IAM policy enforcement is critical to access control boundaries.

Affected products

  • '@hulumi/policies < 1.3.2

Related CVE's

  • CVE-2026-82860

Categories

  • Cloud & Virtualization
  • Identity & Access
  • Supply Chain & Dependencies