⌁ CyberSecurityBoardThreat Intel · CVEs · Products
Critical CVEs

CVE-2026-82857 — Critical vulnerability brief

August 31, 2026CVSS 9.3

hulumi versions before v1.3.2 contain a privilege escalation vulnerability in the weekly integration IAM policy that allows role lifecycle operations on af-e2e-* roles without sufficient boundary restrictions. Attackers with the documented principal can create persistent higher-privilege roles in the sandbox account.

CVSS base score: 9.3 / 10

View NVD record