← Terug naar overzicht

CVE-2026-82861 affects @hulumi/policies versions before 1.3.2, exposing a parent spoof bypass vulnerability in the policy evaluation engine. Attackers can submit falsified SecureBucket parent evidence during policy evaluation, tricking the validator into treating unsafe bucket configurations as compliant. This allows bypassing security policy checks entirely, potentially exposing misconfigured or insecure storage buckets. The vulnerability is resolved in version 1.3.2 of the package. It has been disclosed via GitHub Security Advisories and VulnCheck. The issue is particularly concerning for environments relying on @hulumi/policies for enforcing storage security posture. No active exploitation has been publicly confirmed, but the bypass nature warrants high-priority patching.

Affected products

  • '@hulumi/policies < 1.3.2

Related CVE's

  • CVE-2026-82861

Categories

  • Cloud & Virtualization
  • Database & Storage
  • Supply Chain & Dependencies