Privilege Escalation in hulumi via IAM Policy Misconfiguration
hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that permits unauthorized role lifecycle operations on af-e2e-* roles.
CVE search metadata
CVE search record: CVE-2026-82857. Severity: critical. CVSS: 9.8. KEV: no. Product: hulumi (< 1.3.2). Brief: Privilege Escalation in hulumi via IAM Policy Misconfiguration. Brief link: https://feed.craftedsignal.io/briefs/2026-08-cve-2026-82857/
What's new
hulumi versions before v1.3.2 are susceptible to a privilege escalation vulnerability rooted in the weekly integration IAM policy. The flaw specifically concerns the inadequate application of boundary restrictions on af-e2e-* roles. This lack of constraint allows attackers who possess the documented principal to execute role lifecycle operations that they are not authorized to perform. By leveraging this vulnerability, an attacker can create persistent roles with higher privileges than their own within the sandbox account. This vulnerability is significant for defenders because it allows for lateral movement and long-term access persistence within cloud environments, effectively bypassing established identity-based security controls.
Impact
Successful exploitation of this vulnerability allows an attacker to escalate privileges within the sandbox account environment. By creating persistent, high-privilege roles, an attacker can maintain unauthorized access, exfiltrate sensitive data, or compromise additional cloud infrastructure services linked to the affected sandbox account.
Recommendation
- Upgrade the hulumi installation to version v1.3.2 or later immediately.
- Review all existing IAM policies and role definitions associated with af-e2e-* roles in the sandbox account for unexpected persistence or high-privilege assignments.
- Apply strict boundary conditions to all roles used for integration testing to ensure they cannot exceed the intended scope of their function.
Immediate actions
Upgrade hulumi to v1.3.2 or later.
Mitigations
Review and restrict IAM boundary policies for all af-e2e-* roles.
CVE-2026-82857