CVE-2026-82855
CRITICAL
NVD
CVSS Score
9.8
Severity
CRITICAL
Published
Aug 31, 2026
Vendor
unknown
Description
@hulumi/policies versions before 1.3.2 contain an evidence validation bypass vulnerability in Cloudflare and deployment-governance validators that allows attackers to suppress violations by submitting unrelated compliant evidence. Attackers can use evidence from different zones, hostnames, origins, or repositories to bypass security guardrails for unrelated resources in the same stack.