Skip to content

Weekly integration IAM policy enabled role privilege escalation

High
kerberosmansour published GHSA-35qr-vx94-m5x3 May 15, 2026

Software

kerberosmansour/hulumi weekly integration IAM policy guide

Affected versions

< v1.3.2

Patched versions

v1.3.2

Description

Impact: repository revisions before v1.3.2 documented a weekly integration IAM policy that allowed role lifecycle operations on af-e2e-* roles without sufficient boundary or trust restrictions. Code running with that documented principal could create persistent higher-privilege roles in the sandbox account.

Patched in v1.3.2: unnecessary inline-policy and trust-update permissions were removed and the guide was updated.

Remediation: replace any deployed weekly integration IAM policy with the v1.3.2 or later template.

Severity

High

CVE ID

No known CVE

Weaknesses

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. Learn more on MITRE.