HIGHVulnerability

CVE-2026-82861

@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass security policy checks by providing falsified evidence, causing the validator to miss unsafe bucket configurations.

Properties

severity
HIGH
score
7.5
epss_score
0.00256
cve_id
CVE-2026-82861
vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
published_at
2026-08-31T09:17:06.500
last_modified
2026-09-02T16:17:26.880
epss_percentile
0.1711

Related Entities (3)

ENRICHED_BY (1)

[Source]FIRST EPSS

HAS_WEAKNESS (1)

[Weakness]Improper Access Control

DESCRIBED_BY (1)

[Source]NVD

Explore deeper with Ninja Signal's threat intelligence graph

CVE-2026-82861 — Ninja Signal Threat Intelligence | Ninja Signal