SEPTEMBER 15, 2026
Live Feed
Back to database
Case File

CVE-2026-82859

CRITICAL · CVSS 9.8 EPSS 0.30% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-15

CyberRota Analysis

AI-Generated

Hulumi versions prior to 1.3.2 are vulnerable due to a flawed deployment SCP template that permits tag-on-create bypasses, undermining hulumi:iac-role protections. This vulnerability allows attackers to circumvent intended IAM boundary restrictions, potentially leading to unauthorized access and privilege escalation in downstream deployments. Organizations using affected versions should prioritize immediate updates to mitigate this critical risk.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

Detected Signals
exploit
GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82859
Severity
CRITICAL
CVSS
9.8
EPSS
0.30%

Original NVD Description

hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments.