SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-48034

HIGH · CVSS 8.5 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-24 · Last synced 2026-08-23

CyberRota Analysis

AI-Generated

Hulumi, an open-source toolkit for Pulumi, is vulnerable to a bypass attack that allows unauthorized access to resources through decoy sibling resources targeting a different bucket, affecting versions prior to 1.4.0. This vulnerability could lead to unauthorized data exposure or manipulation, posing a significant risk to users managing cloud infrastructure with this toolkit. Organizations utilizing Hulumi should prioritize upgrading to version 1.4.0 to mitigate potential security risks.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-48034
Severity
HIGH
CVSS
8.5
EPSS
0.26%

Original NVD Description

Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, there is a bypass via decoy sibling resources targeting a different bucket. This issue has been patched in version 1.4.0.