CRITICAL 10.0 NVD
CVE-2026-103956
Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority
Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to the application API in a deployment where no identity provider is configured.
To remediate this issue, users should upgrade to version 1.6.1 or later.
References
- https://aws.amazon.com/security/security-bulletins/2026-124-aws/
- https://github.com/awslabs/loom/releases/tag/v1.6.1
- https://github.com/awslabs/loom/security/advisories/GHSA-vgmj-998f-r8mp
This critical severity vulnerability with a CVSS score of 10.0 was published on 2026-10-02 via NVD.
Risk Timeline
CVE Disclosed2026-10-02 · -1 days ago
Remediation Resources
vulnfeed aggregates 10027 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.