Impact
The vulnerability arises from insufficient boundary restrictions in hulumi’s weekly integration IAM policy, enabling attackers with a documented principal to perform role lifecycle operations on af-e2e-* roles. This allows the creation of persistent, higher-privilege roles within the sandbox account, effectively elevating the attacker’s privileges beyond their intended scope.
Affected Systems
The flaw affects all releases of hulumi before version 1.3.2, developed by kerberosmansour. Users running any pre‑1.3.2 release are impacted if they rely on the weekly integration IAM policy that includes af‑e2e‑* role lifecycle permissions.
Risk and Exploitability
The CVSS score of 9.3 highlights a high‑severity risk, and although the EPSS score is unavailable, the lack of boundary limits means this vulnerability can be exploited by any account possessing the documented principal. The vulnerability is not listed in CISA KEV, yet its severity and wide impact warrant immediate attention. Exploitation requires no special pre‑conditions beyond the existing permissions, and once leveraged, the attacker can establish lasting elevated roles within the sandbox environment.
OpenCVE Enrichment