top of page
perceptive_background_267k.jpg

hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-…

Published:

31 augustus 2026 om 00:00:00

Alert date:

31 augustus 2026 om 12:05:43

Source:

nvd.nist.gov

Click to open the original link from this advisory

Cloud & Virtualization, Identity & Access

hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy. The flaw allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers who possess the documented principal can exploit this to create persistent higher-privilege roles within the sandbox account. This effectively enables unauthorized elevation of cloud permissions. The vulnerability is tracked as CVE-2026-82857 and has been patched in hulumi v1.3.2. It is classified as high severity due to the potential for persistent privilege escalation in cloud IAM environments. Organizations using affected versions should upgrade immediately to mitigate risk.

Technical details

Mitigation steps:

Affected products:

hulumi

Related links:

Related CVE's:

Related threat actors:

IOC's:

This article was created with the assistance of AI technology by Perceptive.

© 2025 by Perceptive Security. All rights reserved.

email: info@perceptivesecurity.com

Deze website toont informatie afkomstig van externe bronnen; Perceptive aanvaardt geen verantwoordelijkheid voor de juistheid, volledigheid of actualiteit van deze informatie.

bottom of page