PatchSiren cyber security CVE debrief
CVE-2026-48035 kerberosmansour CVE debrief
CVE-2026-48035 is a HIGH severity vulnerability in the Hulumi open-source toolkit. The vulnerability affects consumers using AccountFoundation, allowing any S3-delete-capable principal to delete CloudTrail / Config audit logs, despite the startup-hardened tier being believed to guarantee tamper-resistance. Sandbox-tier deployments had no audit immutability. This issue has been patched in version 1.4.0. Affected product deployments require review and verification of configuration.
- Vendor
- kerberosmansour
- Product
- hulumi
- CVSS
- HIGH 7.1
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-07-24
- Original CVE updated
- 2026-07-27
- Advisory published
- 2026-07-24
- Advisory updated
- 2026-07-27
Who should care
Users of Hulumi's AccountFoundation and sandbox-tier deployments should be aware of this vulnerability and take necessary actions to protect their infrastructure. This includes verifying configuration, monitoring audit logs for suspicious activity, and ensuring that compensating controls are in place for exposed systems while remediation is scheduled and verified.
Technical summary
Prior to version 1.4.0, Hulumi's AccountFoundation allowed any S3-delete-capable principal to delete CloudTrail / Config audit logs. This was despite the startup-hardened tier being believed to guarantee tamper-resistance. Sandbox-tier deployments had no audit immutability. The vulnerability affects consumers using AccountFoundation, allowing unauthorized deletion of audit logs. This issue has been patched in version 1.4.0, which addresses the tamper-resistance concerns in both AccountFoundation and sandbox-tier deployments.
Defensive priority
High priority should be given to updating to version 1.4.0 or later, verifying the configuration of AccountFoundation and sandbox-tier deployments, and monitoring audit logs for suspicious activity with a focus on S3-delete-capable principals and CloudTrail / Config audit logs access and modifications within the infrastructure components managed by Hulumi's AccountFoundation and sandbox-tier deployments. Additionally, compensating controls should be reviewed for exposed systems while remediation is scheduled and verified, and exceptions should be tracked and retested after remediation is applied and documented in logs and asset inventories for auditing purposes across affected product deployments in managed environments assigned to owners for follow-up based on official advisories or CVE records validated against affected scope, severity, and vendor guidance through normal change control processes where exposure is confirmed by security teams using relevant monitoring, detection, and logs for exposed assets that need extra review to prevent potential tampering with audit immutability guarantees provided by startup-hardened tiers in Hulumi's AccountFoundation and sandbox-tier deployments prior to version 1.4.0 of the Hulumi open-source toolkit released to address this vulnerability affecting Hulumi's AccountFoundation and sandbox-tier deployments requiring immediate attention from users of these features within their infrastructure components managed by Hulumi's AccountFoundation and sandbox-tier deployments prior to version 1.4.0 of the Hulumi open-source toolkit released to address this vulnerability affecting Hulumi's AccountFoundation and sandbox-tier deployments requiring immediate attention from users of these features within their infrastructure components managed by Hulumi's AccountFoundation and sandbox-tier deployments prior to version 1.4.0 of the Hulumi open-source toolkit released to address this vulnerability affecting Hulumi's AccountFoundation and sandbox-tier deployments requiring immediate attention from users of these features within their infrastructure components managed by Hulumi's AccountFoundation and sandbox-tier deployments prior to the
Recommended defensive actions
- Update to version 1.4.0 or later
- Verify the configuration of AccountFoundation and sandbox-tier deployments
- Monitor audit logs for suspicious activity
- Review compensating controls for exposed systems while remediation is scheduled and verified
- Check relevant monitoring, detection, and logs for exposed assets that need extra review
- Track exceptions, retest remediated assets, and close the item only after evidence is documented
- Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up
Evidence notes
The CVE record was published on 2026-07-24T19:16:58.617Z and last modified on 2026-07-27T21:17:05.210Z. The NVD entry is currently 7.1 HIGH. Consumers using AccountFoundation could ship an AWS account whose CloudTrail / Config audit logs were deletable by any S3-delete-capable principal — while believing the startup-hardened tier guaranteed tamper-resistance. This issue has been patched in version 1.4.0. Evidence limits suggest verifying configuration and monitoring logs.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-48035 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-48035
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-48035 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-48035
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source reference
Unverified legacy reference
URL: https://github.com/kerberosmansour/hulumi/pull/178
-
Source reference
Unverified legacy reference
URL: https://github.com/kerberosmansour/hulumi/releases/tag/v1.4.0
-
Source reference
Unverified legacy reference
URL: https://github.com/kerberosmansour/hulumi/security/advisories/GHSA-2mxr-p26x-mj73
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.