Description
hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account.
Published: 2026-08-31
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability arises from insufficient boundary restrictions in hulumi’s weekly integration IAM policy, enabling attackers with a documented principal to perform role lifecycle operations on af-e2e-* roles. This allows the creation of persistent, higher-privilege roles within the sandbox account, effectively elevating the attacker’s privileges beyond their intended scope.

Affected Systems

The flaw affects all releases of hulumi before version 1.3.2, developed by kerberosmansour. Users running any pre‑1.3.2 release are impacted if they rely on the weekly integration IAM policy that includes af‑e2e‑* role lifecycle permissions.

Risk and Exploitability

The CVSS score of 9.3 highlights a high‑severity risk, and although the EPSS score is unavailable, the lack of boundary limits means this vulnerability can be exploited by any account possessing the documented principal. The vulnerability is not listed in CISA KEV, yet its severity and wide impact warrant immediate attention. Exploitation requires no special pre‑conditions beyond the existing permissions, and once leveraged, the attacker can establish lasting elevated roles within the sandbox environment.

Generated by OpenCVE AI on August 31, 2026 at 10:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to hulumi v1.3.2 or later, which removes the unsafe privileges in the IAM policy.
  • If an upgrade cannot occur immediately, modify the weekly integration IAM policy to restrict or eliminate role lifecycle operations on af‑e2e-* roles, ensuring boundaries align with least‑privilege principles.
  • Review and adjust any custom IAM policy additions that interact with af‑e2e-* roles to prevent unintended elevation of privileges.

Generated by OpenCVE AI on August 31, 2026 at 10:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 10:30:00 +0000

Type Values Removed Values Added
First Time appeared Kerberosmansour
Kerberosmansour hulumi
Vendors & Products Kerberosmansour
Kerberosmansour hulumi

Mon, 31 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Description hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account.
Title hulumi before v1.3.2 Privilege Escalation via IAM Policy
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Kerberosmansour Hulumi
cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-31T08:46:30.487Z

Reserved: 2026-08-31T08:37:27.053Z

Link: CVE-2026-82857

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T09:17:05.920

Modified: 2026-08-31T09:17:05.920

Link: CVE-2026-82857

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T10:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management