Skip to content

CIS 1.16 admin policy bypass for inline and attached IAM policies

High
kerberosmansour published GHSA-4xrh-5m3m-328w May 15, 2026

Package

npm @hulumi/policies (npm)

Affected versions

< 1.3.2

Patched versions

1.3.2

Description

Impact: @hulumi/policies versions before 1.3.2 did not fully inspect inline and attached IAM policy evidence for the administrator-policy guardrail, so some admin-equivalent policy paths could pass policy evaluation.

Patched in 1.3.2: the validator inspects the affected policy shapes and includes regression tests.

Remediation: upgrade @hulumi/policies to 1.3.2 or later.

Severity

High

CVE ID

No known CVE

Weaknesses

Improper Privilege Management

The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor. Learn more on MITRE.