hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy. The flaw allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers who possess the documented principal can exploit this to create persistent higher-privilege roles within the sandbox account. This effectively enables unauthorized elevation of cloud permissions. The vulnerability is tracked as CVE-2026-82857 and has been patched in hulumi v1.3.2. It is classified as high severity due to the potential for persistent privilege escalation in cloud IAM environments. Organizations using affected versions should upgrade immediately to mitigate risk.