CVE-2026-82858
Received Received - Intake

Remote Code Execution in @hulumi/drift

Vulnerability report for CVE-2026-82858, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulnCheck

Description

@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe reconciliation operations.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hulumi drift to 1.3.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-345 The product does not sufficiently verify the origin or authenticity of data, in a way that causes it to accept invalid data.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-82858 affects the @hulumi/drift package versions before 1.3.2. It allows externally supplied execute plans to be accepted without proper validation of their origin or authenticity. Attackers can exploit this to submit malicious plans that bypass security checks and perform unsafe reconciliation operations.

Detection Guidance

Check installed versions of @hulumi/drift using npm list @hulumi/drift. If the version is below 1.3.2, the system is vulnerable. Inspect logs for unexpected execute plan submissions or reconciliation operations.

Impact Analysis

This vulnerability enables attackers to execute unauthorized or malicious operations through the drift package, potentially leading to data breaches, system compromise, or unauthorized changes. The high CVSS scores (9.3 and 9.8) indicate significant risk of confidentiality, integrity, and availability impacts.

Compliance Impact

This vulnerability could lead to unauthorized data access or modifications, violating GDPR's integrity and confidentiality principles or HIPAA's security requirements. Organizations using affected versions may face compliance violations, legal penalties, and reputational damage due to insufficient data authenticity verification.

Mitigation Strategies

Upgrade @hulumi/drift to version 1.3.2 or later immediately. Ensure provenance validation is enabled in configuration. Monitor for suspicious reconciliation activities.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82858. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart