CVE-2026-48037 Details
Description
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, AccountFoundation reuse paths silently downgrade GuardDuty / Security Hub posture. This issue has been patched in version 1.4.0.
A vulnerability in Hulumi's AccountFoundation component, prior to version 1.4.0, allows for the silent downgrading of GuardDuty and Security Hub postures when reusing existing AWS services. This issue arises because the reuse paths do not verify the operational status or configuration of the imported services, potentially leading to misrepresented compliance and threat detection capabilities.
Upgrade to Hulumi version 1.4.0 or later. After upgrading, GuardDuty reuse will verify that the imported detector is active and correctly configured, while Security Hub reuse will retain subscriptions on account deletion.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jul 24, 2026CISA-ADP
Assessed Jul 27, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://github.com/kerberosmansour/hulumi/pull/178 | [email protected] | Source CodeVendor |
| https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0 | [email protected] | Release NotesVendor |
| https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-cj8g-prcm-mfg5 | [email protected] | AdvisoryRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-693 | Protection Mechanism Failure | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| kerberosmansour hulumi | < 1.4.0 (semver) |
CPE
Remediation
| |
| kerberosmansour hulumi-baseline | All versions |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 27, 2026 | CVE Modified | CISA-ADP |
| Jul 24, 2026 | New CVE Received | [email protected] |
Volerion