What is CVE-2026-48037?
The CVE-2026-48037 vulnerability in the Hulumi toolkit allows AccountFoundation reuse paths to silently downgrade the security posture of AWS GuardDuty and Security Hub. This issue affects versions prior to 1.4.0 and must be mitigated by immediately upgrading to version 1.4.0.
Azərbaycanca: Hulumi alətində aşkar edilmiş CVE-2026-48037 zəifliyi AccountFoundation təkrar istifadə yolları vasitəsilə AWS GuardDuty və Security Hub təhlükəsizlik mövqeyinin səssizcə aşağı salınmasına səbəb olur. Bu problem 1.4.0 versiyasından əvvəlki versiyalara təsir edir və dərhal 1.4.0 versiyasına yenilənməklə aradan qaldırılmalıdır.
FAQ2
Which cloud security services' posture can CVE-2026-48037 silently downgrade?
This vulnerability can silently downgrade the security posture of AWS GuardDuty and Security Hub.
To which version of the Hulumi toolkit must be upgraded to mitigate CVE-2026-48037?
This issue affects versions prior to 1.4.0, so it must be mitigated by immediately upgrading to version 1.4.0.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.