ZeroHour

CVE-2026-82863

niche

Incomplete CloudTrail selector tampering detection in @hulumi/baseline

CVSS 4.0
8.7 high
EPSS
<1%p4
Published
()
Modified
AI analysis

Versions of the @hulumi/baseline package before 1.3.2 fail to fully detect changes made to AWS CloudTrail event selectors, leaving a coverage gap in audit-logging configuration monitoring (CWE-778). The flaw is triggered when a party with permissions in the monitored AWS account modifies CloudTrail event selectors — for example narrowing which management or data events are recorded — while baseline is relying on CloudTrail events to flag such changes. Because these tampering events are not completely detected, an attacker can reduce or disable portions of an account's audit trail and operate with a reduced chance of being observed by downstream audit monitoring. Any deployment running @hulumi/baseline prior to 1.3.2 to watch AWS CloudTrail logging configuration is affected. There is no public proof-of-concept, the issue is not in CISA KEV, and EPSS (0.1%, 4th percentile) indicates low near-term exploitation likelihood, with no known exploitation in the wild.

What to do: Upgrade @hulumi/baseline to version 1.3.2 or later to restore full CloudTrail selector tampering detection. In the interim, independently monitor CloudTrail event selector changes via CloudTrail management events (PutEventSelectors, UpdateTrail, StopLogging), EventBridge alerts, or AWS Config rules, and review recent event selector changes in your accounts for signs of tampering.

Affected
hulumi @hulumi/baselineall versions before 1.3.2
Estimated exposure
nicheunknown; expected to be small (no public install or deployment metrics available) — No download counts or deployment data were provided for the @hulumi/baseline package, and as a specialized AWS audit tooling package rather than a mass-market product its installed base is presumed niche but cannot be quantified from…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring.

Weakness
CWE-778
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.