


Perceptive Security
SOC/SIEM Consultancy

@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during p…
Published:
31 August 2026 at 00:00:00
Alert date:
31 August 2026 at 23:17:03
Source:
nvd.nist.gov
Supply Chain & Dependencies, Cloud & Virtualization, Database & Storage
CVE-2026-82861 affects @hulumi/policies versions before 1.3.2, exposing a parent spoof bypass vulnerability in the policy evaluation engine. Attackers can submit falsified SecureBucket parent evidence during policy evaluation, tricking the validator into treating unsafe bucket configurations as compliant. This allows bypassing security policy checks entirely, potentially exposing misconfigured or insecure storage buckets. The vulnerability is resolved in version 1.3.2 of the package. It has been disclosed via GitHub Security Advisories and VulnCheck. The issue is particularly concerning for environments relying on @hulumi/policies for enforcing storage security posture. No active exploitation has been publicly confirmed, but the bypass nature warrants high-priority patching.
Technical details
Mitigation steps:
Affected products:
@hulumi/policies < 1.3.2
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82861
https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-g43v-9x7q-83pq
https://www.vulncheck.com/advisories/hulumi-policies-before-1.3.2-securebucket-parent-spoof-bypass
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
