Authentication Flaw in Loom for AWS Affects AWS Services
CVE-2026-103956

10CRITICAL

Key Information:

Vendor

Aws

Status
Vendor
CVE Published:
2 October 2026

What is CVE-2026-103956?

An authentication flaw in Loom for AWS versions prior to 1.6.1 exposes the system to unauthorized remote actors. This vulnerability enables such actors to gain super-admin access to the agent control plane, allowing them to register tool servers, access stored integration credentials, and alter IAM role policies linked to managed agent roles. This can be achieved with any request to the application API in setups lacking an identity provider, thus posing a significant risk. Users are urged to upgrade to version 1.6.1 or later to mitigate this issue.

Affected Version(s)

loom 0 < 1.6.1

References

CVSS V4

Score:
10
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.