Cyber & AI intelligence
Wasteland.
Briefs indexed2348
Issues26
Published Mondays07:30 CT
⚡ Active KEV CVE-2026-82860 2026-08-31

CVE-2026-82860: Critical IAM Guardrail Bypass in @hulumi/policies

"A critical (CVSS 9.8) flaw in the `@hulumi/policies` npm package may allow attackers to construct admin-equivalent IAM policy paths that are not caught by the administrator-policy guardrail, and it is fixed in version…"

A critical (CVSS 9.8) flaw in the @hulumi/policies npm package may allow attackers to construct admin-equivalent IAM policy paths that are not caught by the administrator-policy guardrail, and it is fixed in version 1.3.2.

What Is It

@hulumi/policies versions before 1.3.2 fail to fully inspect inline and attached IAM policy evidence when enforcing the administrator-policy guardrail. Because the check does not cover every path by which a principal can obtain admin-equivalent permissions, an attacker may be able to craft policy paths that are not flagged by the guardrail.

The issue is classified as CWE-269 (Improper Privilege Management) and was disclosed by VulnCheck.

Why It Matters

The CVSS 3.1 score is 9.8 (CRITICAL), vector CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, network-reachable, low attack complexity, no privileges, and no user interaction required, with high impact to confidentiality, integrity, and availability. The CVSS 4.0 secondary score is 9.3 (CRITICAL).

The practical risk is one of misplaced assurance: teams relying on the guardrail for IAM policy evaluation may believe privileged grants are being caught when some are not.

There is no CISA KEV entry for this CVE; active exploitation has not been confirmed and no KEV remediation deadline applies. Exploit maturity in the CVSS 4.0 vector is Not Defined.

What's Vulnerable

No CPE entries are currently published for this CVE.

Patch Status

Fixed in 1.3.2. Upgrade @hulumi/policies to 1.3.2 or later. Versions from 0 up to (but not including) 1.3.2 are flagged as affected; 1.3.2 is explicitly marked unaffected.

The CVE was published 2026-08-31 and remains in NVD status "Received," so enrichment data may still change.

Sources