Authentication Flaw in Loom for AWS Affects AWS Services
CVE-2026-103956
10CRITICAL
What is CVE-2026-103956?
An authentication flaw in Loom for AWS versions prior to 1.6.1 exposes the system to unauthorized remote actors. This vulnerability enables such actors to gain super-admin access to the agent control plane, allowing them to register tool servers, access stored integration credentials, and alter IAM role policies linked to managed agent roles. This can be achieved with any request to the application API in setups lacking an identity provider, thus posing a significant risk. Users are urged to upgrade to version 1.6.1 or later to mitigate this issue.
Affected Version(s)
loom 0 < 1.6.1
