What is CVE-2026-48035?
A vulnerability in the Hulumi toolkit (CVE-2026-48035) affects users of AccountFoundation prior to version 1.4.0. In affected versions, provisioned AWS accounts allow any principal with S3 delete permissions to delete CloudTrail and Config audit logs, posing a risk of critical event log loss. Immediate upgrade to Hulumi version 1.4.0 or later is strongly recommended to mitigate this issue.
Azərbaycanca: Hulumi platformasında aşkar edilmiş CVE-2026-48035 zəifliyi AccountFoundation istifadəçilərinə təsir edir. Versiya 1.4.0-dan əvvəlki versiyalarda, yaradılan AWS hesablarında CloudTrail/Config audit log-ları S3 silmə icazəsi olan istənilən principal tərəfindən silinə bilər, bu isə mühüm hadisə qeydlərinin itirilməsi riski yaradır. Təhlükəsizlik üçün dərhal Hulumi-ni 1.4.0 və ya daha yuxarı versiyaya yeniləmək tövsiyə olunur.
Related CVEs
link basis: shared vendor: AWS
FAQ2
What platform is affected by CVE-2026-48035?
This vulnerability affects the Hulumi platform, specifically impacting AccountFoundation users.
Which version should be upgraded to in order to mitigate CVE-2026-48035?
It is recommended to upgrade to Hulumi version 1.4.0 or later.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.