Description
@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring.
Published: 2026-08-31
Score: 8.7 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

@hulumi/baseline, a JavaScript library used for infrastructure as code, contains a bug that allows a malicious actor to tamper with AWS CloudTrail event selectors. The library fails to fully detect selector changes, resulting in audit logging coverage gaps. This weakness can be exploited to modify the event selectors without alerting monitoring systems, effectively erasing evidence of configuration changes and enabling further malicious activities.

Affected Systems

The vulnerability affects all installations of @hulumi/baseline older than version 1.3.2. Any environment that relies on this library to enforce or validate AWS CloudTrail selector configurations is susceptible.

Risk and Exploitability

The CVSS score of 8.7 classifies the flaw as high severity. Although the EPSS score is not available, the lack of a KEV listing does not diminish the risk to systems that rely on robust audit trails. Attackers would need to execute or influence code that uses the impacted baseline library to modify CloudTrail selectors, but once the modification occurs, existing detection mechanisms may not notice the change. The likely attack vector involves manipulating configuration scripts or deployment artifacts that employ @hulumi/baseline to manage CloudTrail settings.

Generated by OpenCVE AI on August 31, 2026 at 10:25 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade @hulumi/baseline to version 1.3.2 or later so that selector tampering is correctly detected.
  • If an upgrade is delayed, implement a manual audit check of CloudTrail event selectors immediately after deployment or code changes.
  • Enable additional monitoring such as CloudWatch alerts on changes to CloudTrail configurations to provide additional detection coverage.

Generated by OpenCVE AI on August 31, 2026 at 10:25 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 31 Aug 2026 09:00:00 +0000

Type Values Removed Values Added
Description @hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring.
Title @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection
Weaknesses CWE-778
References
Metrics cvssV3_1

{'score': 3.3, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N'}

cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: VulnCheck

Published:

Updated: 2026-08-31T10:55:23.605Z

Reserved: 2026-08-31T08:37:53.169Z

Link: CVE-2026-82863

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-31T09:17:06.790

Modified: 2026-08-31T09:17:06.790

Link: CVE-2026-82863

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-31T10:30:17Z

Weaknesses