IAM Role Policy Bypass in Hulumi Open-Source Toolkit from Kerberos Mansour
CVE-2026-48032

8.3HIGH

Key Information:

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-48032?

The Hulumi toolkit, developed by Kerberos Mansour, contains a vulnerability that allows IAM-role policy checks to be bypassed when the role trusts multiple OIDC providers. This flaw can compromise the security of applications that rely on the toolkit for managing cloud and platform infrastructure components. Users are advised to upgrade to version 1.4.0, where this issue has been addressed and patched. For more details, refer to the official advisory and patch notes.

Affected Version(s)

hulumi < 1.4.0

References

CVSS V4

Score:
8.3
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.