SEPTEMBER 18, 2026
Live Feed
Back to database
Case File

CVE-2026-82861

HIGH · CVSS 7.5 EPSS 0.26% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-08-31 · Last synced 2026-09-18

CyberRota Analysis

AI-Generated

Versions of @hulumi/policies prior to 1.3.2 are vulnerable to a parent spoof bypass, enabling attackers to submit falsified SecureBucket parent evidence during policy evaluations. This vulnerability allows the circumvention of critical security policy checks, potentially leading to unsafe bucket configurations. Organizations utilizing this package should prioritize updates to mitigate the risk of unauthorized access and data exposure.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-82861
Severity
HIGH
CVSS
7.5
EPSS
0.26%

Original NVD Description

@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass security policy checks by providing falsified evidence, causing the validator to miss unsafe bucket configurations.