AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials
AWS patched four Loom and SageMaker flaws enabling auth bypass, token theft, SSRF, and cross-user command execution.
AWS fixed four vulnerabilities in the open-source Loom AI agent platform and Amazon SageMaker Unified Studio, disclosed on October 2, 2026. CVE-2026-103956 can give any network client full administrative control of Loom when no identity provider is configured. CVE-2026-103957 and CVE-2026-103958 let users with mcp:write or a2a:write leak OAuth2 tokens or reach internal services, including credential endpoints. CVE-2026-104019 is command injection in SageMaker Space startup scripts that can run code in another member's environment and steal temporary role credentials.