Vulnerability  ·  2026-10-03

Loom for AWS agent control plane: unauthenticated super-admin auth bypass + credential-stealing SSRF (CVE-2026-103956/103957/103958)

VulnerabilityHigh impactGlobalCVE-2026-103956
AWS published security bulletin 2026-124 on 2026-10-02 disclosing three issues in Loom, an AWS Labs open-source AI-agent orchestration platform. CVE-2026-103956 (CVSS 10.0) is a missing-authentication flaw in the auth dependency: with no identity provider configured, any network client can obtain super-admin authority over the agent control plane — registering tool servers, reading stored integration credentials, and rewriting IAM role policies on managed agent roles. CVE-2026-103957/103958 are SSRF issues in OAuth2 discovery and in tool-server/remote-agent connection handling that expose OAuth client secrets, other users' access tokens, and container-role credentials.
This is agent-control-plane compromise of core AI orchestration infrastructure: an attacker who wins CVE-2026-103956 gains the keys to every MCP tool server, integration credential, and IAM role the agents run under, enabling supply-chain-like hijack of the entire agent fleet. The SSRF issues additionally leak the deployment's own AWS container-role credentials, escalating to full AWS account access. CVSS 10.0 on an agent-orchestration control plane makes this the highest-priority agentic finding of the window.
Unauthenticated network requests to the Loom API in a deployment without an IdP obtain full administrative authority over the agent control plane; SSRF paths (crafted OAuth discovery URL or tool-server/A2A connection URL) let an authenticated mcp:write/a2a:write user exfiltrate another user's access token, OAuth client secrets, and read the container-role credential endpoint.
Loom for AWS < 1.6.1 (CVE-2026-103956); < 1.7.0 (CVE-2026-103957, CVE-2026-103958)
Upgrade to Loom 1.7.0 (or 1.6.1 for CVE-2026-103956); patch forks. Workarounds: configure a Cognito/IdP before exposing beyond loopback, clear LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV, restrict mcp:write/a2a:write scope. Rotate OAuth client secrets and IAM role credentials after upgrade (AWS bulletin 2026-124-AWS).
AWS Security Bulletin 2026-124-AWSNVD CVE-2026-103956
See this in the live feed Explore related AI security and governance findings — updated every morning.
Open the feed →