Path Downgrade Vulnerability in Hulumi Toolkit by Kerberos Mansour
CVE-2026-48037

6.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
24 July 2026

What is CVE-2026-48037?

The Hulumi toolkit, designed for secure cloud infrastructure, contains a vulnerability related to the AccountFoundation component. Prior to version 1.4.0, this component allows for the reuse of paths, which can inadvertently lead to a downgrade of the security posture for services such as GuardDuty and Security Hub. This silent downgrade poses significant risks, as it may compromise the security measures expected from these monitoring services. The vulnerability is addressed in version 1.4.0, and users are encouraged to upgrade to mitigate these risks.

Affected Version(s)

hulumi < 1.4.0

References

CVSS V4

Score:
6.3
Severity:
MEDIUM
Confidentiality:
None
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.