Privilege Escalation in hulumi by KerberosMansour
CVE-2026-82857
9.3CRITICAL
What is CVE-2026-82857?
The hulumi product by KerberosMansour exhibits a vulnerability in versions earlier than v1.3.2, allowing unauthorized privilege escalation through improper IAM policy configuration. This flaw enables attackers with the documented principal to perform role lifecycle operations on af-e2e-* roles, circumventing necessary boundary restrictions. Consequently, this could lead to the creation of persistent higher-privilege roles within the sandbox account, posing significant security risks.
Affected Version(s)
hulumi 0 < 1.3.2
hulumi 1.3.2
