---
id: CVE-2026-82861
title: >-
  @hulumi/policies versions before 1.3.2 contain a parent spoof bypass
  vulnerability that allows attackers to submit spoofed SecureBucket parent
  evidence during policy evaluation
summary: >-
  @hulumi/policies versions before 1.3.2 contain a parent spoof bypass
  vulnerability that allows attackers to submit spoofed SecureBucket parent
  evidence during policy evaluation. Attackers can bypass security policy checks
  by providing fa…
severity: high
cvss: 7.5
cvssVector: 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'
cwe:
  - CWE-284
vendor: hulumi
product: policies
affected:
  - policies < 1.3.2
published: '2026-08-31'
updated: '2026-10-08'
sourceUpdated: '2026-10-08T16:17:52.730'
source: NVD
sourceUrl: 'https://nvd.nist.gov/vuln/detail/CVE-2026-82861'
references:
  - url: >-
      https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-g43v-9x7q-83pq
    label: disclosure@vulncheck.com
  - url: >-
      https://www.vulncheck.com/advisories/hulumi-policies-before-1.3.2-securebucket-parent-spoof-bypass
    label: disclosure@vulncheck.com
tags:
  - nvd
  - cve.org
ssvc:
  exploitation: none
  automatable: 'yes'
  technicalImpact: partial
  timestamp: '2026-09-02T15:36:21.346915Z'
epss: 0.00434
epssPercentile: 0.35676
ingestedAt: '2026-10-08T16:52:14.736Z'
---

## Overview

@hulumi/policies versions before 1.3.2 contain a parent spoof bypass vulnerability that allows attackers to submit spoofed SecureBucket parent evidence during policy evaluation. Attackers can bypass security policy checks by providing falsified evidence, causing the validator to miss unsafe bucket configurations.

## Remediation

Refer to the linked advisories for vendor-supplied fixes and affected version ranges.
