Sceawere

Vulnerability Detail

CVE-2026-82855UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

@hulumi/policies Evidence Validation Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
21h ago
Vendor
hulumi
Product
policies
Attack Type
Protection Mechanism Failure
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence. Attackers can use evidence from different zones, hostnames, origins, or repositories to bypass security guardrails for unrelated resources in the same stack.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-31T09:17:05.610Z",
  "pubdate": "2026-08-31T09:17:05.610Z",
  "executiveSummary": "The @hulumi/policies package contains an evidence validation bypass vulnerability affecting Cloudflare and deployment-governance validators in versions prior to 1.3.2.\nThis flaw allows an attacker to bypass security guardrails by submitting valid, compliant evidence originating from an unrelated zone, hostname, origin, or repository.\nBy leveraging cross-resource evidence, an attacker can effectively suppress policy violations, leading to the unauthorized deployment or configuration of insecure resources.\nThe vulnerability represents a significant risk to organizational governance, as security controls intended to enforce compliance can be circumvented via evidence masquerading.\nExploitation requires the attacker to possess the ability to submit evidence to the validation engine, though it does not necessitate administrative privileges within the target resource itself, as the validation logic fails to enforce strict boundary checks between separate infrastructure components.\nThe impact includes the potential for non-compliant infrastructure to bypass mandatory security checks, undermining the integrity of the entire deployment stack managed by @hulumi/policies.",
  "technicalDetails": "The root cause of the vulnerability lies in improper input validation within the Cloudflare and deployment-governance modules of @hulumi/policies. Specifically, the validation logic fails to cryptographically or logically bind submitted evidence to the specific resource instance, zone, or repository being assessed.\nDuring the policy evaluation process, the validator confirms that the provided evidence meets certain compliance criteria (e.g., presence of required security headers, correct configuration settings). However, the implementation does not verify that the metadata associated with the evidence (such as source zone or origin) matches the resource currently undergoing policy enforcement.\nThis lack of context validation allows an attacker to perform an evidence injection attack. The attack flow proceeds as follows: 1) An attacker identifies a target resource protected by @hulumi/policies that would normally trigger a violation due to non-compliance. 2) The attacker identifies a separate, compliant resource within the same stack or organization that they have legitimate access to, or that exposes public, compliant configuration evidence. 3) The attacker intercepts or retrieves the compliant evidence metadata from the unrelated compliant resource. 4) The attacker submits this unrelated compliant evidence during the validation of the non-compliant target resource. 5) The @hulumi/policies engine, failing to perform cross-reference checks between the input evidence and the target resource context, validates the evidence as successful, thereby suppressing the violation flag and allowing the deployment or configuration process to proceed.\nBecause the vulnerability exists in the validation function's logic, no authentication is strictly required beyond the ability to trigger the policy check. The exploitation is largely independent of the attacker's privilege level on the specific target, relying instead on the absence of strict ownership verification within the validator. This results in a total bypass of policy guardrails, permitting the persistence of misconfigured or insecure cloud infrastructure that would otherwise be blocked by the governance framework. The scope of impact is limited to resources governed by the vulnerable @hulumi/policies package versions prior to 1.3.2."
}
CVE-2026-82855: @hulumi/policies Evidence Validation Bypass (CRITICAL Severity, CVSS: 9.8) - Sceawere