Description
@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass security policy checks by providing falsified evidence, causing the validator to miss unsafe bucket configurations.
Published: 2026-08-31
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

This vulnerability allows attackers to submit spoofed parent evidence during policy evaluation, circumventing SecureBucket parent checks. The issue stems from improper access control and enables malicious actors to validate storage buckets that should be blocked, potentially exposing data or granting unauthorized bucket access.

Affected Systems

The affected product is the hulumi/policies library, specifically all releases before version 1.3.2. Any Node.js project that depends on these pre‑1.3.2 releases and uses the library for Cloud bucket policy enforcement is vulnerable.

Risk and Exploitability

The CVSS score of 8.7 indicates high severity. EPSS is not available, so exploitation probability is unknown. The vulnerability is not listed in the CISA KEV catalog. Attackers can exploit the flaw by sending crafted evidence to the policy validator API, a form of remote request that bypasses parent checks. The likely attack vector is through the policy engine’s API endpoint, requiring knowledge of the expected evidence format and access to the validation service. While no public exploit is documented, the combination of a high CVSS score and the potential for data exposure makes the risk high.

Generated by OpenCVE AI on August 31, 2026 at 10:26 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade to hulumi/policies v1.3.2 or newer, which fixes the parent spoof bypass.
  • Re‑enable strict evidence validation in the policy engine to prevent spoofed assertions.
  • Monitor application logs for evidence submissions that do not match expected signatures and alert or block anomalous requests.

Generated by OpenCVE AI on August 31, 2026 at 10:26 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Description @hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass security policy checks by providing falsified evidence, causing the validator to miss unsafe bucket configurations.
Title @hulumi/policies before 1.3.2 SecureBucket Parent Spoof Bypass
Weaknesses CWE-284
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-31T08:46:33.202Z

Reserved: 2026-08-31T08:37:27.054Z

Link: CVE-2026-82861

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T09:17:06.500

Modified: 2026-08-31T09:17:06.500

Link: CVE-2026-82861

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T10:30:17Z

Weaknesses