hulumi versions before v1.3.2 contain a deployment SCP template that allows tag-on-create bypasses for hulumi:iac-role protections. Attackers can bypass intended IAM boundary restrictions by exploiting the weakened SCP template in downstream deployments.
Casky was already ahead
This CVE exploits attack patterns that Casky's 0matched skills already investigate — long before this vulnerability was disclosed. Claude's reasoning model maps these techniques to MITRE ATT&CK, so practitioners who ran these skills have already seen the threat behaviour in their findings.
CVE-2026-82859 is a critical vulnerability in hulumi versions before v1.3.2 that undermines Infrastructure-as-Code (IaC) security controls through a flawed Service Control Policy (SCP) template. The vulnerability allows attackers to bypass tag-on-create restrictions designed to enforce IAM boundary protections on the hulumi:iac-role, enabling privilege escalation and lateral movement within AWS environments. This affects organizations using hulumi for IaC deployments who rely on SCPs as a primary defense mechanism. The 9.8 CVSS score reflects the severity: attackers can circumvent organizational guardrails without authentication, directly accessing resources that should be restricted by policy boundaries.
While this CVE currently maps to zero Casky skills and no specific MITRE ATT&CK techniques, practitioners would detect exploitation patterns through behavioral analysis of IAM activities. Detection would focus on policy enforcement gaps—specifically tag-based access control failures and unexpected role assumption operations that violate SCP intent. Casky's extended reasoning capabilities, paired with Claude AI's cross-domain analysis, would correlate suspicious patterns such as: (1) resources created with bypassed tags that should trigger SCP denials, (2) IAM role assumption succeeding when SCPs should block them, and (3) infrastructure deployments circumventing intended security boundaries. Organizations should immediately audit their hulumi deployments, validate SCP template versions, and monitor for unauthorized resource creation patterns that indicate exploitation of this boundary weakness.
Composite risk scoring from EPSS, CISA KEV, Shodan, and GreyNoise — 21 security APIs correlated into a single Casky Risk Score. Coming in Casky Pro. Join early access →
Casky has 0 skills that investigate the attack patterns behind CVE-2026-82859. Run one and get CVSS-scored findings in 3 minutes.
Run the skill that detects this →© 2026 Casky.AI, Inc. · AI Security Investigation