ZeroHour

CVE-2026-82857

Privilege Escalation via Weekly Integration IAM Policy in hulumi

CVSS 4.0
9.3 critical
EPSS
<1%p21
Published
()
Modified
AI analysis

hulumi versions before v1.3.2 contain an improper privilege management flaw (CWE-269) in the IAM policy attached to its weekly integration, which grants role lifecycle operations on roles named af-e2e-* without sufficient permissions-boundary restrictions. An attacker who can act as the documented integration principal — for example by compromising the credentials or session used by that automation — can create or modify roles matching the af-e2e-* pattern in the sandbox account. Because nothing constrains what those roles may do, the attacker can mint persistent, higher-privilege roles and escalate their access within the sandbox account, with high impact to confidentiality, integrity, and availability per the CVSS 4.0 score of 9.3. Affected users are hulumi deployments relying on the weekly integration IAM policy and the af-e2e-* role namespace in a sandbox account; the size of that population is not publicly documented. There is currently no known exploitation: the flaw is not in CISA KEV, no public proof-of-concept is available, and EPSS assigns only a 0.3% probability of exploitation in the next 30 days.

What to do: Upgrade hulumi to v1.3.2 or later. As interim mitigation, tighten the weekly integration principal's IAM permissions by scoping role lifecycle actions to only the intended roles and applying permissions boundaries to any af-e2e-* role creation. Also audit af-e2e-* roles in the sandbox account for unexpected or overly privileged roles and trust policies, and rotate the integration principal's credentials if tampering is suspected.

Affected
hulumiall versions before v1.3.2
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account.

Weakness
CWE-269
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.