CVE-2026-82859
—Tag-on-Create SCP Bypass Enables IAM Boundary Bypass in hulumi
hulumi versions before v1.3.2 ship a deployment service control policy (SCP) template that fails to properly restrict creation of resources carrying the protected hulumi:iac-role tag, permitting a tag-on-create bypass of the intended protections (CWE-284, improper access control). The flaw is triggered in downstream deployments that applied the supplied SCP template: principals can create resources tagged with hulumi:iac-role even where the policy was meant to limit or gate that action. As a result, an attacker can bypass the intended IAM boundary restrictions the SCP was designed to enforce, weakening the access-control perimeter around the deployment environment. Any organization running hulumi before v1.3.2 that deployed the flawed SCP template in its cloud organization or accounts is affected. Exploitation is not currently observed: there is no public proof-of-concept, the issue is not in CISA KEV, and EPSS estimates only about a 0.3% probability of exploitation within 30 days (23rd percentile).
What to do: Upgrade hulumi to v1.3.2 or later and replace the weakened SCP template in all downstream deployments with the corrected policy. Audit resources created while the flawed template was active, specifically looking for tag-on-create actions that attached the hulumi:iac-role tag from unintended principals, and verify the deployed SCP now denies or restricts such creations as intended.
| hulumi | all versions before v1.3.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments.
- Weakness
- CWE-284
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.