Description
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role trusts multiple OIDC providers. This issue has been patched in version 1.4.0.
Published: 2026-07-24
Score: 8.3 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

Based on the updated description, the vulnerability in Hulumi allows an attacker to bypass IAM‑role policy checks when the role trusts multiple OIDC providers. This flaw corresponds to CWE‑697, an incorrect enforcement of permissions, and by manipulating or adding an OIDC provider that the role accepts, the attacker can obtain permissions that should have been denied, enabling unauthorized access to cloud resources. This bypass is a classic privilege escalation flaw and directly compromises the integrity and confidentiality of the infrastructure managed with Pulumi.

Affected Systems

The affected product is Hulumi released by kerberosmansour. All releases prior to version 1.4.0 are impacted, as the fix was backported and shipped in 1.4.0. Systems that depend on earlier versions of Hulumi for provisioning IAM roles are at risk.

Risk and Exploitability

The CVSS score of 8.3 indicates high severity, but the EPSS score of less than 1 % shows that the likelihood of exploitation in the wild is currently low. It is not listed in the CISA KEV catalog. Based on the updated description, the likely attack vector is an attacker who can control or compromise an OIDC provider that is trusted by a role; once that provider is leveraged, the policy checks are coerced and the attacker can elevate privileges.

Generated by OpenCVE AI on August 3, 2026 at 19:47 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update Hulumi to version 1.4.0 or later where the issue is fixed.
  • Restrict IAM‑role trust relationships to a single OIDC provider or enforce manual validation when multiple providers are used.
  • Audit existing roles to ensure no unintended provider trusts remain.
  • Monitor OIDC provider activity for signs of misuse or unauthorized configuration changes.

Generated by OpenCVE AI on August 3, 2026 at 19:47 UTC.

Tracking

Sign in to view the affected projects.

Advisories
Source ID Title
Github GHSA Github GHSA GHSA-g759-4pxw-6692 @hulumi/policies bypasses IAM-role policy checks when the role trusts multiple OIDC providers
History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
First Time appeared Kerberosmansour
Kerberosmansour hulumi
Vendors & Products Kerberosmansour
Kerberosmansour hulumi

Fri, 24 Jul 2026 19:15:00 +0000

Type Values Removed Values Added
Description Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, IAM-role policy checks can be bypassed when the role trusts multiple OIDC providers. This issue has been patched in version 1.4.0.
Title Hulumi: IAM-role policy checks bypassed when the role trusts multiple OIDC providers
Weaknesses CWE-697
References
Metrics cvssV4_0

{'score': 8.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:N/VI:H/VA:L/SC:N/SI:N/SA:N'}


Subscriptions

Kerberosmansour Hulumi
cve-icon MITRE

Status: PUBLISHED

Assigner: GitHub_M

Published:

Updated: 2026-07-27T17:20:38.935Z

Reserved: 2026-05-20T18:15:53.577Z

Link: CVE-2026-48032

cve-icon Vulnrichment

Updated: 2026-07-27T17:20:34.573Z

cve-icon NVD

Status : Deferred

Published: 2026-07-24T19:16:58.190

Modified: 2026-07-30T16:41:25.650

Link: CVE-2026-48032

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T20:00:12Z

Weaknesses