CVE-2026-82859
hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments.
Package Versions Affected
Automatically patch vulnerabilities without upgrading
CVSS Version



Related Resources
References
https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/82xxx/CVE-2026-82859.json, https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-86q4-r5j3-ff5c, https://nvd.nist.gov/vuln/detail/CVE-2026-82859, https://www.vulncheck.com/advisories/hulumi-before-1.3.2-scp-template-tag-on-create-bypass