AWS Fixes AI Agent Flaws Enabling Authentication Bypass and Credential Theft
AWS patched Loom AI-agent flaws that can bypass authentication, leak OAuth tokens, and expose cloud credentials.
AWS patched four flaws affecting its open-source Loom AI-agent platform and Amazon SageMaker Unified Studio, disclosed in Security Bulletin 2026-124-AWS on October 2, 2026. CVE-2026-103956 let any network client gain full administrative access to Loom deployments before 1.6.1 that had no identity provider. CVE-2026-103957 and CVE-2026-103958, fixed in Loom 1.7.0, let users with mcp:write or a2a:write leak OAuth secrets or tokens and read internal services, including cloud credential endpoints. CVE-2026-104019 is a command-injection bug in SageMaker Studio Space startup that could steal another project member's temporary credentials; patched images apply on restart.