CVE-2026-82863CWE-778

CVE-2026-82863

Low · published August 31, 2026

CVSS v3.1
3.3
EPSS
0%
Percentile
4.1
In the wild
Unconfirmed
What it is

@hulumi/baseline versions before 1.3.2 fail to fully detect CloudTrail selector tampering events, reducing audit logging configuration change coverage. Attackers can modify CloudTrail event selectors without complete detection, potentially evading audit trail monitoring.

The record
Technical detail
CVSS v3.1
3.3 · LOW
Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:L/A:N
CVSS v4.0
8.7 · CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N
EPSS
0.00145 · 4.1th percentile
Weakness
CWE-778 · Insufficient Logging
Published
2026-08-31T13:17Z
References (2)
EPSS history
Timeline
  • 01 SEP 03:32Z
    EPSS moved — → 0%
    epss
  • 31 AUG 08:46Z
    @hulumi/baseline before 1.3.2 CloudTrail Selector Tampering Detection
    cvelistv5