← Terug naar overzicht

A security vulnerability in the @hulumi/policies npm package affects versions before 1.3.2. The package fails to fully inspect inline and attached IAM policy documents when evaluating the administrator-policy guardrail. This allows attackers to craft admin-equivalent policy paths that bypass policy evaluation controls. The flaw effectively grants unauthorized administrative access to those who exploit it. The vulnerability has been assigned CVE-2026-82860 and is rated high severity. Users are advised to upgrade to version 1.3.2 or later to remediate the issue. The advisory has been published on both the GitHub Security Advisories page and VulnCheck.

Affected products

  • '@hulumi/policies < 1.3.2

Related CVE's

  • CVE-2026-82860

Categories

  • Cloud & Virtualization
  • Identity & Access
  • Supply Chain & Dependencies