๐Ÿ” CVE Alert

CVE-2026-82863

LOW 3.3

@hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection

CVSS Score
3.3
EPSS Score
0.0%
EPSS Percentile
0th

@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring.

CWE CWE-778
Vendor hulumi
Product baseline
Published Aug 31, 2026
Stay Ahead of the Next One

Get instant alerts for hulumi baseline

Be the first to know when new low vulnerabilities affecting hulumi baseline are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
Attack Vector
Local
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
None
Integrity
Low
Availability
None

Affected Versions

hulumi / baseline
0 < 1.3.2

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-gfp8-mp24-5vxg vulncheck.com: https://www.vulncheck.com/advisories/hulumi-baseline-before-1.3.2-cloudtrail-selector-tampering-detection