CVE-2026-82857
Received Received - Intake

Privilege Escalation in Hulumi via IAM Policy Misconfiguration

Vulnerability report for CVE-2026-82857, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulnCheck

Description

hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
hulumi hulumi to 1.3.2 (exc)
kerberosmansour hulumi to 1.3.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-82857 is a privilege escalation vulnerability in hulumi versions before v1.3.2. It exists due to an overly permissive weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without proper boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account.

Detection Guidance

Check hulumi version with 'hulumi version' and compare against v1.3.2. Inspect IAM policies for weekly integration roles with 'aws iam list-policies --scope Local' and review attached policies for excessive permissions. Look for af-e2e-* roles with lifecycle operations.

Impact Analysis

This vulnerability allows attackers to escalate privileges and create persistent higher-privilege roles in your sandbox account. This could lead to unauthorized access, data breaches, or further compromise of your cloud environment if exploited.

Mitigation Strategies

Upgrade hulumi to v1.3.2 or later. Replace the weekly integration IAM policy with the updated template from v1.3.2. Remove unnecessary inline-policy and trust-update permissions from affected roles.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82857. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart