Description
@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equivalent policy paths that bypass policy evaluation controls.
Published: 2026-08-31
Score: 9.3 Critical
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability in @hulumi/policies versions prior to 1.3.2 undermines the administrator‑policy guardrail by not fully validating policy evidence. Attackers can craft admin‑equivalent IAM policy paths that bypass policy evaluation, enabling them to gain administrative privileges that the guardrail is designed to prevent.

Affected Systems

The affected product is the hulumi policies package (@hulumi/policies). Any deployment using versions earlier than 1.3.2 is susceptible. Applications that rely on this package for access control should verify their installed version and upgrade accordingly.

Risk and Exploitability

With a CVSS score of 9.3, the vulnerability is high severity. EPSS data is not available, and the issue is not listed in CISA’s KEV catalog, but the nature of the flaw suggests that remote exploitation is possible if the attacker can submit or influence policy definitions. Once privilege escalation is achieved, the attacker can modify resources, access sensitive data, and disrupt services. Immediate remediation is strongly advised.

Generated by OpenCVE AI on August 31, 2026 at 10:27 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade @hulumi/policies to version 1.3.2 or later.
  • Revoke or audit all IAM policies that were created before the update to ensure none contain escape vectors.
  • Configure your IaC tooling to enforce strict policy validation or enable additional security controls that reject unauthorized admin‑equivalent policies.

Generated by OpenCVE AI on August 31, 2026 at 10:27 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Description @hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail. Attackers can craft admin-equivalent policy paths that bypass policy evaluation controls.
Title @hulumi/policies before 1.3.2 Admin Policy Bypass
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 9.8, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-31T08:46:32.506Z

Reserved: 2026-08-31T08:37:27.054Z

Link: CVE-2026-82860

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T09:17:06.353

Modified: 2026-08-31T09:17:06.353

Link: CVE-2026-82860

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T10:30:17Z

Weaknesses
  • CWE-269

    Improper Privilege Management