Vulnerability in Open-source Toolkit for AWS Account Management by Hulumi
CVE-2026-48035

7.1HIGH

Key Information:

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-48035?

The Hulumi toolkit, designed for secure AWS account management, contains a vulnerability that allows for the deletion of CloudTrail and Config audit logs by any principal with S3 delete capabilities. This oversight misleads users into believing they had ensured tamper-resistance with the startup-hardened tier. Furthermore, deployments in the sandbox tier lack any form of audit immutability, compounding the security risks. The issue has been addressed in version 1.4.0, emphasizing the need for users to update immediately to ensure the integrity of their audit logs.

Affected Version(s)

hulumi < 1.4.0

References

CVSS V4

Score:
7.1
Severity:
HIGH
Confidentiality:
None
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.