Vulnerability in Open-source Toolkit for AWS Account Management by Hulumi
CVE-2026-48035
7.1HIGH
What is CVE-2026-48035?
The Hulumi toolkit, designed for secure AWS account management, contains a vulnerability that allows for the deletion of CloudTrail and Config audit logs by any principal with S3 delete capabilities. This oversight misleads users into believing they had ensured tamper-resistance with the startup-hardened tier. Furthermore, deployments in the sandbox tier lack any form of audit immutability, compounding the security risks. The issue has been addressed in version 1.4.0, emphasizing the need for users to update immediately to ensure the integrity of their audit logs.
Affected Version(s)
hulumi < 1.4.0
