LIVE · cybersecurity feed
Live wire
cve recordcritical

CVE-2026-82858

Published
CVSS9.8
Severitycritical
WeaknessCWE-345
ExploitedNot in CISA KEV

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Description

@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe reconciliation operations.

References

← Back to the CVE Tracker

Our coverage of CVE-2026-82858

No stories yet. This page updates automatically when we publish reporting that references CVE-2026-82858.