← Back to overview

hulumi versions prior to v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy. The flaw allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with access to the documented principal can exploit this to create persistent higher-privilege roles within the sandbox account. This represents a significant cloud identity and access management risk. The vulnerability has been assigned CVE-2026-82857 and is documented across NVD, GitHub Security Advisories, and VulnCheck. Remediation requires upgrading to hulumi v1.3.2 or later. No exploitation details beyond the documented principal are specified in the advisory.

Affected products

  • hulumi

Related CVE's

  • CVE-2026-82857

Categories

  • Cloud & Virtualization
  • Identity & Access