


Perceptive Security
SOC/SIEM Consultancy

hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-…
Published:
31 augustus 2026 om 00:00:00
Alert date:
31 augustus 2026 om 12:05:43
Source:
nvd.nist.gov
Cloud & Virtualization, Identity & Access
hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy. The flaw allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers who possess the documented principal can exploit this to create persistent higher-privilege roles within the sandbox account. This effectively enables unauthorized elevation of cloud permissions. The vulnerability is tracked as CVE-2026-82857 and has been patched in hulumi v1.3.2. It is classified as high severity due to the potential for persistent privilege escalation in cloud IAM environments. Organizations using affected versions should upgrade immediately to mitigate risk.
Technical details
Mitigation steps:
Affected products:
hulumi
Related links:
https://nvd.nist.gov/vuln/detail/CVE-2026-82857
https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-35qr-vx94-m5x3
https://www.vulncheck.com/advisories/hulumi-before-1.3.2-privilege-escalation-via-iam-policy
Related CVE's:
Related threat actors:
IOC's:
This article was created with the assistance of AI technology by Perceptive.
