CVE-2026-82861
—Parent evidence spoofing bypass in @hulumi/policies policy validation
Versions of the @hulumi/policies package before 1.3.2 fail to adequately verify the parent evidence supplied for SecureBucket policies during policy evaluation (CWE-284). An attacker who can control the evidence submitted to the validator can submit falsified parent evidence, making an insecurely configured bucket appear to pass its security policy checks. The attacker gains a bypass of security controls enforced by the validator, allowing unsafe bucket configurations to go undetected; the flaw does not itself grant access to systems. Anyone using affected versions of @hulumi/policies to evaluate SecureBucket policies — for example in automated compliance or CI/CD checks — is affected. No public proof-of-concept or in-the-wild exploitation is currently known, and EPSS assigns a low 0.3% probability of exploitation in the next 30 days.
What to do: Upgrade @hulumi/policies to version 1.3.2 or later. Until upgraded, do not rely solely on validator output for SecureBucket compliance: treat submitted parent evidence as untrusted, review pipeline inputs that feed evidence to the validator, and independently verify that bucket configurations (e.g., encryption and public-access settings) are actually safe.
| hulumi @hulumi/policies | all versions before 1.3.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass security policy checks by providing falsified evidence, causing the validator to miss unsafe bucket configurations.
- Weakness
- CWE-284
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.