{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/tags/identity-access-management/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:hulumi:hulumi:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":9.8,"id":"CVE-2026-82857"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["hulumi (\u003c 1.3.2)"],"_cs_severities":["critical"],"_cs_tags":["privilege-escalation","cloud-security","identity-access-management","iac","vulnerability","rce","execution"],"_cs_type":"advisory","_cs_vendors":["hulumi"],"content_html":"\u003cp\u003ehulumi versions before v1.3.2 are susceptible to a privilege escalation vulnerability rooted in the weekly integration IAM policy. The flaw specifically concerns the inadequate application of boundary restrictions on af-e2e-* roles. This lack of constraint allows attackers who possess the documented principal to execute role lifecycle operations that they are not authorized to perform. By leveraging this vulnerability, an attacker can create persistent roles with higher privileges than their own within the sandbox account. This vulnerability is significant for defenders because it allows for lateral movement and long-term access persistence within cloud environments, effectively bypassing established identity-based security controls.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation of this vulnerability allows an attacker to escalate privileges within the sandbox account environment. By creating persistent, high-privilege roles, an attacker can maintain unauthorized access, exfiltrate sensitive data, or compromise additional cloud infrastructure services linked to the affected sandbox account.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the hulumi installation to version v1.3.2 or later immediately.\u003c/li\u003e\n\u003cli\u003eReview all existing IAM policies and role definitions associated with af-e2e-* roles in the sandbox account for unexpected persistence or high-privilege assignments.\u003c/li\u003e\n\u003cli\u003eApply strict boundary conditions to all roles used for integration testing to ensure they cannot exceed the intended scope of their function.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-31T11:18:08Z","date_published":"2026-08-31T11:16:47Z","id":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-82857/","summary":"hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that permits unauthorized role lifecycle operations on af-e2e-* roles.","title":"Privilege Escalation in hulumi via IAM Policy Misconfiguration","url":"https://feed.craftedsignal.io/briefs/2026-08-cve-2026-82857/"}],"language":"en","title":"CraftedSignal Threat Feed - Identity-Access-Management","version":"https://jsonfeed.org/version/1.1"}