在 v1.3.2 之前的 hulumi 版本中,其每周集成的 IAM 策略存在一个权限提升漏洞。该策略对 af-e2e-* 角色执行角色生命周期操作时,缺乏足够的边界限制。拥有文档中所述主体(principal)权限的攻击者,能够在沙箱账户中创建持久化的更高权限角色。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| kerberosmansour | hulumi | 0 ~ 1.3.2 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-82859 | 9.8 CRITICAL | hulumi before v1.3.2 SCP Template Tag-on-Create Bypass |
| CVE-2026-82862 | 8.4 HIGH | Hulumi before v1.3.2 Helper Script Shadowing via Workspace Files |
No comments yet