CVE-2026-82858

@hulumi/drift versions before 1.3.2 accept externally supplied execute plans without sufficient provenance validation, allowing untrusted reconciliation input to be treated as trusted. Attackers can supply malicious execute plans that bypass security checks to perform unsafe reconciliation operations.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-31 09:17

Updated : 2026-08-31 20:52


NVD link : CVE-2026-82858

Mitre link : CVE-2026-82858

CVE.ORG link : CVE-2026-82858


JSON object : View

Products Affected

No product.

CWE
CWE-345

Insufficient Verification of Data Authenticity