CVE-2026-82863
Received Received - Intake

CloudTrail Selector Tampering Detection Bypass in @hulumi/baseline

Vulnerability report for CVE-2026-82863, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-31

Last updated on: 2026-08-31

Assigner: VulnCheck

Description

@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-31
Last Modified
2026-08-31
Generated
2026-08-31
AI Q&A
2026-08-31
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
hulumi baseline to 1.3.2 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-778 When a security-critical event occurs, the product either does not record the event or omits important details about the event when logging it.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability affects @hulumi/baseline versions before 1.3.2. It fails to fully detect CloudTrail selector tampering events, meaning attackers can modify CloudTrail event selectors without complete detection. This reduces audit logging coverage for configuration changes.

Detection Guidance

To detect this vulnerability, check if your @hulumi/baseline version is below 1.3.2. Run commands like 'npm list @hulumi/baseline' or 'yarn list @hulumi/baseline' to verify the installed version. Compare it against the latest version 1.3.2 or higher.

Impact Analysis

Attackers could evade audit trail monitoring by modifying CloudTrail event selectors without detection. This may allow unauthorized changes to go unnoticed, potentially leading to undetected security breaches or compliance violations.

Compliance Impact

This vulnerability reduces audit logging coverage, which may impact compliance with standards requiring thorough audit trails like GDPR or HIPAA. Insufficient logging could lead to non-compliance and potential penalties.

Mitigation Strategies

Immediately upgrade @hulumi/baseline to version 1.3.2 or later. After upgrading, rerun affected previews or checks to ensure expanded detection coverage is active. Verify CloudTrail event selectors are properly monitored for tampering.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-82863. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart