{"id":"CVE-2026-82863","title":"@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage","summary":"@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potential…","severity":"low","cvss":3.3,"cvssVector":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N","cwe":["CWE-778"],"vendor":"hulumi","product":"baseline","affected":["baseline < 1.3.2"],"published":"2026-08-31","updated":"2026-10-08","sourceUpdated":"2026-10-08T16:17:53.043","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-82863","references":[{"url":"https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-gfp8-mp24-5vxg","label":"disclosure@vulncheck.com"},{"url":"https://www.vulncheck.com/advisories/hulumi-baseline-before-1.3.2-cloudtrail-selector-tampering-detection","label":"disclosure@vulncheck.com"}],"tags":["nvd","cve.org"],"ssvc":{"exploitation":"none","automatable":"yes","technicalImpact":"partial","timestamp":"2026-08-31T10:50:32.681291Z"},"epss":0.00243,"epssPercentile":0.14208,"ingestedAt":"2026-10-08T16:52:14.736Z","slug":"CVE-2026-82863","body":"## Overview\n\n@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":18,"depthScoreParts":{"impact":18.2,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}