Vulnerability  ·  2026-10-03

Loom for AWS: unauthenticated authentication bypass grants super-admin over the AI agent control plane (CVSS 10.0)

VulnerabilityHigh impactGlobalCVE-2026-103956
AWS disclosed via coordinated disclosure that a missing-authentication issue in Loom (CWE-306/1188) let any remote network client obtain super-admin authority over the agent control plane in deployments with no identity provider configured. The fix was released in 1.6.1 (2026-08-04); AWS urges upgrading to 1.7.0 and patching forked/derived code.
Loom is an AI agent orchestration platform that manages agent roles, MCP tool servers and integration credentials in AWS accounts. Full agent-control-plane takeover plus credential read and IAM-role-policy write means attacker-controlled agents could be registered and provisioned with existing managed-agent IAM roles, moving from zero privilege to infrastructure-level compromise of the AI deployment.
When no identity provider (Cognito or external IdP) is configured, any unauthenticated request to the Loom application API acquires full administrative authority — register tool servers, read stored integration credentials, and rewrite IAM role policies attached to managed agent roles.
Loom for AWS (awslabs/loom) < 1.6.1
Upgrade to Loom ≥1.6.1 (latest 1.7.0); ensure an identity provider is fully configured before the backend is reachable beyond loopback; keep LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV unset in deployed environments. Advisory: https://aws.amazon.com/security/security-bulletins/2026-124-aws/
NVD CVE-2026-103956AWS Security Bulletin 2026-124GitHub advisory GHSA-vgmj-998f-r8mp
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →