---
id: CVE-2026-82858
title: >-
  @hulumi/drift versions before 1.3.2 accept externally supplied execute plans
  without sufficient provenance validation, allowing untrusted reconciliation
  input to be treated as trusted
summary: >-
  @hulumi/drift versions before 1.3.2 accept externally supplied execute plans
  without sufficient provenance validation, allowing untrusted reconciliation
  input to be treated as trusted. Attackers can supply malicious execute plans
  that by…
severity: critical
cvss: 9.8
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'
cwe:
  - CWE-345
vendor: hulumi
product: drift
affected:
  - drift < 1.3.2
published: '2026-08-31'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:52.123'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82858'
references:
  - url: >-
      https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-2ffm-hxrq-qqmm
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/hulumi-drift-before-1.3.2-unsafe-execute-plan-acceptance
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: total
  timestamp: '2026-08-31T10:59:15.542770Z'
epss: 0.00285
epssPercentile: 0.19217
ingestedAt: '2026-10-08T16:52:14.736Z'
---

## Overview

@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe reconciliation operations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
