CVE-2026-48035 Details
Description
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal — while believing the startup-hardened tier guaranteed tamper-resistance. Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded). This issue has been patched in version 1.4.0.
A vulnerability in Hulumi's AccountFoundation component, prior to version 1.4.0, allowed AWS accounts to be configured in a way that deleted CloudTrail and Config audit logs could be erased by any principal with S3 delete permissions. This undermined the intended tamper-resistance of the startup-hardened tier. Additionally, accounts deployed in the sandbox tier had no audit immutability whatsoever. The vulnerability arose because the startup-hardened audit bucket was not properly locked to prevent deletions, and sandbox-tier deployments completely bypassed audit protections.
Users can upgrade to Hulumi version 1.4.0, which addresses the vulnerability by implementing a proper retention policy on audit logs and restoring immutable audit capture for sandbox accounts. Instructions for upgrading are available in the Hulumi repository.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 24, 2026CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kerberosmansour/hulumi/pull/178 | [email protected] | Issue TrackingVendor |
| https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0 | [email protected] | Release NotesVendor |
| https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-2mxr-p26x-mj73 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-1059 | Insufficient Technical Documentation | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Hulumi | < 1.4.0 (semver) |
CPE
Remediation
| |
| Hulumi AccountFoundation | < 1.4.0 (semver) |
CPE
Remediation
| |
| Hulumi Baseline | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 24, 2026 | New CVE Received | [email protected] |
Volerion