CVE-2026-82857

Severity CVSS v4.0:
CRITICAL
Type:
CWE-269 Improper Privilege Management
Publication date:
31/08/2026
Last modified:
31/08/2026

Description

hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account.