Impact
This vulnerability is a missing authentication flaw in the authentication dependency of AWS Loom. The flaw allows an attacker with no prior credentials to gain super‑admin authority over the agent control plane. By sending any request to the application API when the deployment lacks an identity provider, an adversary can register tool servers, read stored integration credentials, and rewrite IAM role policies attached to managed agent roles. The weakness is an example of lacking authentication (CWE-306) and potentially improper authorization, which can lead to complete control over Loom.
Affected Systems
Affected systems are installations of AWS Loom prior to version 1.6.1. The flaw applies to deployments where no identity provider has been configured. Users running Loom 1.5.x, 1.6.0 or earlier, especially in environments that rely on the default unauthenticated access, are susceptible.
Risk and Exploitability
The CVSS score of 10 indicates a critical severity, and although an EPSS score is not available, the flaw is not yet listed in CISA KEV, suggesting it may not have observed exploits yet. Nonetheless, the lack of authentication and the broad remote API access mean the attack could be performed from any network with visibility to the Loom API. The risk remains high, and an upgrade or other mitigations should be applied promptly.
OpenCVE Enrichment