CVE-2026-82863
nicheIncomplete CloudTrail selector tampering detection in @hulumi/baseline
Versions of the @hulumi/baseline package before 1.3.2 fail to fully detect changes made to AWS CloudTrail event selectors, leaving a coverage gap in audit-logging configuration monitoring (CWE-778). The flaw is triggered when a party with permissions in the monitored AWS account modifies CloudTrail event selectors — for example narrowing which management or data events are recorded — while baseline is relying on CloudTrail events to flag such changes. Because these tampering events are not completely detected, an attacker can reduce or disable portions of an account's audit trail and operate with a reduced chance of being observed by downstream audit monitoring. Any deployment running @hulumi/baseline prior to 1.3.2 to watch AWS CloudTrail logging configuration is affected. There is no public proof-of-concept, the issue is not in CISA KEV, and EPSS (0.1%, 4th percentile) indicates low near-term exploitation likelihood, with no known exploitation in the wild.
What to do: Upgrade @hulumi/baseline to version 1.3.2 or later to restore full CloudTrail selector tampering detection. In the interim, independently monitor CloudTrail event selector changes via CloudTrail management events (PutEventSelectors, UpdateTrail, StopLogging), EventBridge alerts, or AWS Config rules, and review recent event selector changes in your accounts for signs of tampering.
| hulumi @hulumi/baseline | all versions before 1.3.2 |
Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.
@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring.
- Weakness
- CWE-778
- Vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
In the news0 stories
No ingested article mentions this CVE yet.