Admin Policy Bypass in @hulumi/policies Product by Hulumi
CVE-2026-82860
9.3CRITICAL
What is CVE-2026-82860?
The @hulumi/policies library, specifically in versions prior to 1.3.2, contains a significant vulnerability where inline and attached IAM policies are not fully vetted. This oversight allows malicious actors to devise admin-equivalent policy paths that can evade the established policy evaluation controls, enabling them to gain unauthorized administrative access.
Affected Version(s)
policies 0 < 1.3.2
policies 1.3.2
