Executive brief
hulumi is an infrastructure-as-code tool that manages AWS identity and access control policies. Versions before 1.3.2 contain a flawed Service Control Policy (SCP) template that allows attackers to bypass tag-based access restrictions on IAM roles, potentially granting unauthorized permissions within AWS environments. This weakens the security boundaries intended to protect infrastructure deployments.
Technical details
The vulnerability is an improper access control flaw (CWE-284) in the deployment SCP template shipped with hulumi. The template fails to properly enforce tag-on-create restrictions for the hulumi:iac-role, allowing attackers to bypass intended IAM boundary protections. The attack requires network access and no authentication, as it exploits a weakness in the SCP logic itself that applies to any downstream deployments using the affected template. An attacker can create IAM entities with elevated permissions that should have been restricted, potentially gaining administrative access to AWS resources. The vulnerability was patched in v1.3.2, which tightened the SCP template and added regression checks.
Affected products
- hulumi hulumi before 1.3.2
Timeline
- 2026-05-15: disclosed: GitHub Security Advisory GHSA-86q4-r5j3-ff5c published
- 2026-08-31: advisory: CVE-2026-82859 published on NVD
- 2026-05-15: patched: Fix available in v1.3.2