Sceawere

Vulnerability Detail

CVE-2026-82859UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

Hulumi SCP Tag-On-Create Bypass

Vulnerability Metadata

Severity
Critical
Score / CVSS
9.8
Creation Date
21h ago
Vendor
kerberosmansour
Product
hulumi
Attack Type
Improper Access Control
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Attack Complexity
LOW

Narrative and Response

Description

hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "9.8",
  "pubDate": "2026-08-31T09:17:06.210Z",
  "pubdate": "2026-08-31T09:17:06.210Z",
  "executiveSummary": "Hulumi versions prior to v1.3.2 are susceptible to a security configuration vulnerability within their deployment Service Control Policy (SCP) template. This flaw facilitates a tag-on-create bypass, effectively undermining the integrity of established hulumi:iac-role protections. By exploiting this weakened SCP, an attacker can circumvent mandatory IAM boundary restrictions imposed on downstream deployments. The vulnerability allows unauthorized actors or compromised service accounts to modify the intended authorization model during the resource provisioning phase. The risk implication is significant, as the bypass grants attackers the ability to escalate privileges or perform actions that would otherwise be denied by the organization's security guardrails. Successful exploitation requires the ability to trigger a deployment process that utilizes the vulnerable SCP template. Because these guardrails are intended to enforce structural security, the failure of the SCP template invalidates the principle of least privilege across the affected infrastructure.",
  "technicalDetails": "The vulnerability resides in the static SCP template configuration utilized by hulumi versions before v1.3.2. Specifically, the SCP fails to strictly enforce conditions that prevent tag manipulation during the resource creation lifecycle. In cloud environments, 'tag-on-create' is a common administrative function that, if not explicitly restricted within an SCP or IAM policy, can be leveraged to alter the metadata of resources being provisioned. Because hulumi:iac-role protections rely on identifying and isolating resources based on these specific tags, the bypass effectively decouples the resource from the restrictive IAM boundary that should govern its lifecycle.\nThe root cause is an overly permissive SCP logic that does not sufficiently validate the tag keys and values against the required hulumi:iac-role attribute during the 'Create' API call. An attacker with sufficient permissions to initiate a deployment can supply arbitrary tags that conflict with, or ignore, the required security attributes. By successfully injecting or omitting these tags during the create action, the attacker forces the resource to inherit a context where the IAM boundary is either downgraded or rendered ineffective.\nThe attack flow proceeds as follows: First, the attacker identifies a deployment workflow that consumes the vulnerable hulumi SCP template. Second, the attacker initiates a provisioning request while intentionally manipulating the tagging parameters of the cloud resource being created. Third, due to the lack of restrictive 'Deny' conditions in the SCP template regarding unauthorized tag keys, the control plane accepts the request, bypassing the hulumi:iac-role protective layer. Finally, the resource is deployed with an incorrect security context, allowing the attacker to assume unauthorized roles or perform administrative actions that the security boundary was designed to prevent. This post-exploitation state allows for lateral movement, privilege escalation, and persistent unauthorized access to downstream resources managed within the hulumi framework."
}
CVE-2026-82859: Hulumi SCP Tag-On-Create Bypass (CRITICAL Severity, CVSS: 9.8) - Sceawere