CVE-2026-82861 affects @hulumi/policies versions before 1.3.2, exposing a parent spoof bypass vulnerability. Attackers can submit spoofed SecureBucket parent evidence during policy evaluation, causing the validator to incorrectly assess bucket configurations. By providing falsified evidence, attackers can bypass security policy checks entirely. This results in unsafe bucket configurations going undetected by the policy enforcement system. The vulnerability is fixed in version 1.3.2 of the @hulumi/policies package. The issue is documented in both the NVD and VulnCheck advisories, as well as a GitHub security advisory.