Sceawere

Vulnerability Detail

CVE-2026-82861UPDATED Verified Sceawere Triage Sources: NVD / CISA KEV

@hulumi/policies Parent Spoof Vulnerability

Vulnerability Metadata

Severity
High
Score / CVSS
7.5
Creation Date
21h ago
Vendor
hulumi
Product
policies
Attack Type
Improper Access Control
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Attack Complexity
LOW

Narrative and Response

Description

@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass security policy checks by providing falsified evidence, causing the validator to miss unsafe bucket configurations.

Executive Summary

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Executive Summary Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Technical Details

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Detailed Technical Analysis Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Mitigations

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Remediation & Mitigations Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

References

Lorem ipsum dolor sit amet, consectetur adipiscing elit. Sed do eiusmod tempor incididunt ut labore et dolore magna aliqua. Ut enim ad minim veniam, quis nostrud exercitation ullamco laboris nisi ut aliquip ex ea commodo consequat.

Duis aute irure dolor in reprehenderit in voluptate velit esse cillum dolore eu fugiat nulla pariatur. Excepteur sint occaecat cupidatat non proident, sunt in culpa qui officia deserunt mollit anim id est laborum.

Intelligence References Locked

Sign up to unlock professional threat analysis, mitigations, and indicator signatures.

Additional Metadata

{
  "score": "7.5",
  "pubDate": "2026-08-31T09:17:06.500Z",
  "pubdate": "2026-08-31T09:17:06.500Z",
  "executiveSummary": "The @hulumi/policies package is susceptible to a parent spoof bypass vulnerability affecting versions prior to 1.3.2. This flaw resides in the policy evaluation logic for SecureBucket configurations.\nThe vulnerability allows an attacker to manipulate evidence submitted during the validation process, specifically by providing falsified parent metadata. By successfully injecting spoofed SecureBucket parent evidence, an adversary can bypass critical security policy checks.\nThis bypass results in the validator failing to identify unsafe bucket configurations, potentially allowing insecure storage instances to persist or be deployed within the infrastructure.\nThe risk implication is significant as it undermines the integrity of automated policy enforcement, enabling the bypass of security guardrails. Exploitation requires the ability to interact with the policy evaluation interface and supply malicious evidence parameters to the validation engine.",
  "technicalDetails": "The root cause of this vulnerability lies in the insufficient validation and trust placed in the evidence provided during the evaluation of SecureBucket policies within @hulumi/policies versions prior to 1.3.2.\nDuring the policy evaluation lifecycle, the validator consumes evidence related to parent-child relationships for SecureBucket resources. The implementation fails to cryptographically verify or perform server-side cross-referencing of the 'parent' identifier provided in the submission, assuming the input data is authoritative.\nAttack flow for exploitation involves the following steps: First, an attacker identifies a target environment protected by @hulumi/policies. Second, the attacker crafts a malicious request intended to trigger a policy check for a bucket configuration. Third, within this request, the attacker includes a spoofed parent evidence object that declares the bucket as belonging to a trusted or pre-validated parent hierarchy, despite the actual configuration being insecure.\nUpon receiving this input, the validator consumes the falsified evidence without checking its integrity or origin. Because the validator trusts the provided parent metadata to ascertain the security context of the bucket, it erroneously concludes that the bucket adheres to safety policies due to the apparent inheritance from a compliant parent.\nConsequently, the policy engine marks the unsafe bucket as compliant, effectively bypassing the security controls that would otherwise reject the configuration. This allows for the deployment or retention of buckets with overly permissive access controls, improper encryption settings, or other security misconfigurations that would normally violate the organizational policy enforced by @hulumi/policies.\nThe vulnerability does not necessarily require high-level authentication if the policy evaluation endpoint is exposed to the service submission pipeline. Post-exploitation, an attacker can maintain insecure infrastructure that remains invisible to compliance reporting, facilitating further lateral movement or data exfiltration from the misconfigured buckets."
}
CVE-2026-82861: @hulumi/policies Parent Spoof Vulnerability (HIGH Severity, CVSS: 7.5) - Sceawere