Description
Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to the application API in a deployment where no identity provider is configured.



To remediate this issue, users should upgrade to version 1.6.1 or later.
Published: 2026-10-02
Score: 10 Critical
EPSS: n/a
KEV: No
Impact: Remote Privilege Escalation to Super‑Admin
Action: Patch Now
AI Analysis

Impact

This vulnerability is a missing authentication flaw in the authentication dependency of AWS Loom. The flaw allows an attacker with no prior credentials to gain super‑admin authority over the agent control plane. By sending any request to the application API when the deployment lacks an identity provider, an adversary can register tool servers, read stored integration credentials, and rewrite IAM role policies attached to managed agent roles. The weakness is an example of lacking authentication (CWE-306) and potentially improper authorization, which can lead to complete control over Loom.

Affected Systems

Affected systems are installations of AWS Loom prior to version 1.6.1. The flaw applies to deployments where no identity provider has been configured. Users running Loom 1.5.x, 1.6.0 or earlier, especially in environments that rely on the default unauthenticated access, are susceptible.

Risk and Exploitability

The CVSS score of 10 indicates a critical severity, and although an EPSS score is not available, the flaw is not yet listed in CISA KEV, suggesting it may not have observed exploits yet. Nonetheless, the lack of authentication and the broad remote API access mean the attack could be performed from any network with visibility to the Loom API. The risk remains high, and an upgrade or other mitigations should be applied promptly.

Generated by OpenCVE AI on October 2, 2026 at 20:24 UTC.

Remediation

No solution or workaround provided in the CVE record.

OpenCVE Recommended Actions

  • Upgrade to AWS Loom 1.6.1 or later to receive the authentication fix
  • Configure and enforce an identity provider for the Loom application to prevent unauthenticated API requests
  • After upgrading, audit IAM role policies attached to managed agent roles to ensure no unintended changes were made

Generated by OpenCVE AI on October 2, 2026 at 20:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 02 Oct 2026 19:30:00 +0000


Fri, 02 Oct 2026 19:15:00 +0000

Type Values Removed Values Added
Description Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to the application API in a deployment where no identity provider is configured. To remediate this issue, users should upgrade to version 1.6.1 or later.
Title Missing authentication for critical function in Loom for AWS
Weaknesses CWE-1188
CWE-306
References
Metrics cvssV3_1

{'score': 10, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 10, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: AMZN

Published:

Updated: 2026-10-02T21:09:30.961Z

Reserved: 2026-10-01T14:59:36.204Z

Link: CVE-2026-103956

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-10-02T19:16:39.750

Modified: 2026-10-02T20:17:00.257

Link: CVE-2026-103956

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-02T20:30:16Z

Weaknesses
  • CWE-1188

    Initialization of a Resource with an Insecure Default

  • CWE-306

    Missing Authentication for Critical Function