What happened
AWS disclosed via coordinated disclosure that a missing-authentication issue in Loom (CWE-306/1188) let any remote network client obtain super-admin authority over the agent control plane in deployments with no identity provider configured. The fix was released in 1.6.1 (2026-08-04); AWS urges upgrading to 1.7.0 and patching forked/derived code.
Why it matters
Loom is an AI agent orchestration platform that manages agent roles, MCP tool servers and integration credentials in AWS accounts. Full agent-control-plane takeover plus credential read and IAM-role-policy write means attacker-controlled agents could be registered and provisioned with existing managed-agent IAM roles, moving from zero privilege to infrastructure-level compromise of the AI deployment.
Attack vector
When no identity provider (Cognito or external IdP) is configured, any unauthenticated request to the Loom application API acquires full administrative authority — register tool servers, read stored integration credentials, and rewrite IAM role policies attached to managed agent roles.
Affected systems
Loom for AWS (awslabs/loom) < 1.6.1
Mitigation
Upgrade to Loom ≥1.6.1 (latest 1.7.0); ensure an identity provider is fully configured before the backend is reachable beyond loopback; keep LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV unset in deployed environments. Advisory: https://aws.amazon.com/security/security-bulletins/2026-124-aws/