What is CVE-2026-48033?
CVE-2026-48033 affects the open-source toolkit 'Hulumi', allowing policy packs to be bypassed using a forged Pulumi-URN logical name. This issue has been patched in version 1.4.0, so users should update immediately.
Azərbaycanca: CVE-2026-48033, 'Hulumi' adlı açıq mənbəli alətdə aşkarlanıb. Saxta 'Pulumi-URN' məntiqi adı ilə təhlükəsizlik siyasət paketlərinin (policy packs) yan keçilməsinə imkan verir. 1.4.0 versiyasına yeniləməklə problemi həll etmək olar.
FAQ2
Which product is affected by CVE-2026-48033?
CVE-2026-48033 affects the open-source toolkit 'Hulumi'.
How can CVE-2026-48033 be remediated?
This issue has been patched in version 1.4.0, so updating will resolve the problem.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.