CRITICAL 10.0 NVD

CVE-2026-103956

Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority

Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to the application API in a deployment where no identity provider is configured. To remediate this issue, users should upgrade to version 1.6.1 or later.

References

Published: 2026-10-02 · Source: NVD · Feed updated: 2026-10-02
This critical severity vulnerability with a CVSS score of 10.0 was published on 2026-10-02 via NVD.

Risk Timeline

CVE Disclosed2026-10-02 · -1 days ago

Remediation Resources

vulnfeed aggregates 10027 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.