CVE-2026-48035
Hulumi is an open-source toolkit that ships secure-by-default cloud and platform infrastructure components for Pulumi. Prior to version 1.4.0, consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal — while believing the startup-hardened tier guaranteed tamper-resistance. Sandbox-tier deployments had no audit immutability at all (defects 1 and 3 compounded). This issue has been patched in version 1.4.0.
Scoring
- Severity
- HIGH
- CVSS base score
- 7.1
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
- EPSS probability
- 0.26%
- CWE
- CWE-1059
- Published
- 2026-07-24
- Last modified
- 2026-07-27
Affected products
- kerberosmansour hulumi
Weakness type
Related vulnerabilities
- CVE-2026-59084 — Apache Tomcat: EncryptInterceptor requirements not clearly documented
- CVE-2022-3270 — Incomplete Documentation of remote functions in FESTO products.