{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/cpes/cpe2.3ahulumipolicies/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hulumi:policies:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.5,"id":"CVE-2026-82861"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["policies (\u003c 1.3.2)"],"_cs_severities":["high"],"_cs_tags":["supply-chain","vulnerability","cloud-security","iam"],"_cs_type":"advisory","_cs_vendors":["hulumi"],"content_html":"\u003cp\u003eThe @hulumi/policies library, used to enforce security configurations for cloud storage buckets, contains a critical flaw identified as CVE-2026-82861. In versions prior to 1.3.2, the library is susceptible to a parent spoofing vulnerability. This flaw allows an attacker to submit falsified SecureBucket parent evidence during the policy evaluation process. By manipulating this evidence, an attacker can deceive the validation logic into accepting unsafe bucket configurations that would otherwise be rejected by security policies. This vulnerability effectively undermines the integrity of automated security governance for cloud storage assets, potentially exposing sensitive data through misconfigured, publicly accessible, or unencrypted storage buckets. Organizations relying on this library for automated cloud security posture management must update to version 1.3.2 or later to restore policy integrity.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows attackers to bypass security enforcement mechanisms, potentially leading to the deployment or maintenance of insecurely configured storage buckets. This creates opportunities for unauthorized data access, exfiltration, or modification depending on the nature of the bucket misconfigurations that the policy engine fails to catch.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the @hulumi/policies package to version 1.3.2 or later in all application and build-pipeline dependencies.\u003c/li\u003e\n\u003cli\u003eAudit existing infrastructure-as-code (IaC) templates and deployment logs that utilize @hulumi/policies for evidence of potential bypasses or misconfigured bucket permissions.\u003c/li\u003e\n\u003cli\u003eReview cloud bucket access logs for anomalies in storage configurations that were marked as compliant by the policy engine during the vulnerable period.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T13:58:01Z","date_published":"2026-08-31T11:17:59Z","id":"https://feed.craftedsignal.io/briefs/2026-08-hulumi-policies-bypass/","summary":"The @hulumi/policies package before version 1.3.2 is vulnerable to a parent spoofing attack that allows unauthorized actors to bypass security policy enforcement during bucket configuration validation.","title":"Security Policy Bypass in @hulumi/policies via Parent Spoofing","url":"https://feed.craftedsignal.io/briefs/2026-08-hulumi-policies-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Cpe:2.3:a:hulumi:policies:*:*:*:*:*:*:*:*","version":"https://jsonfeed.org/version/1.1"}