AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials
AWS patched four Loom and SageMaker flaws enabling auth bypass, token theft, SSRF, and cross-user command execution.
AWS fixed four vulnerabilities in the open-source Loom AI agent platform and Amazon SageMaker Unified Studio, disclosed on October 2, 2026. CVE-2026-103956 can give any network client full administrative control of Loom when no identity provider is configured. CVE-2026-103957 and CVE-2026-103958 let users with mcp:write or a2a:write leak OAuth2 tokens or reach internal services, including credential endpoints. CVE-2026-104019 is command injection in SageMaker Space startup scripts that can run code in another member's environment and steal temporary role credentials.
- CVE-2026-103956 grants Loom admin control when no identity provider is configured.
- CVE-2026-103957 can leak OAuth2 secrets or access tokens to attacker endpoints.
- CVE-2026-103958 is SSRF that may expose temporary AWS credentials.
- CVE-2026-104019 injects commands in another SageMaker Space member's environment.
- Upgrade Loom to 1.7.0 and restart Studio Spaces for patched images.
Vulnerabilities mentionedAll →
- CVE-2026-10395610.0<1%Missing authentication in Loom for AWS control planepublished · Loom for AWS PoC
- CVE-2026-1039588.3—Authenticated SSRF in Loom for AWS before 1.7.0
Full article630 words · extracted from gbhackers.com · click to collapse
AWS has released security fixes for four vulnerabilities affecting its open-source Loom AI agent orchestration platform and Amazon SageMaker Unified Studio.
The flaws could allow attackers to bypass authentication, steal OAuth2 tokens and temporary cloud credentials, access internal services, and execute arbitrary code in another user’s SageMaker environment.
AWS disclosed the issues in security bulletins published on October 2, 2026. Three flaws affect Loom for AWS, an AWS Labs open-source platform designed to orchestrate AI agents, while the fourth impacts the SageMaker Distribution startup process used by SageMaker Unified Studio.
AWS AI Agent Vulnerabilities
AWS recommends that Loom users upgrade to version 1.7.0 and that SageMaker customers restart affected Studio Spaces to obtain patched images.
The highest-impact Loom flaw, tracked as CVE-2026-103956, affects versions earlier than 1.6.1. It stems from an issue in Loom’s authentication dependency that could let any network client gain complete administrative authority over the agent control plane if a deployment does not have an identity provider configured.
An attacker could use this access to register malicious tool servers, retrieve stored integration credentials, and alter IAM role policies associated with managed agent roles.
AWS classified the issue under CWE-306, Missing Authentication for Critical Function, and CWE-1188, Insecure Default Initialization of Resource Permissions.
AWS fixed CVE-2026-103956 in Loom version 1.6.1, released on August 4, 2026. However, customers should move directly to Loom 1.7.0 because it includes fixes for the additional token-disclosure and internal-network access flaws.
CVE-2026-103957 affects Loom releases before version 1.7.0 and concerns unsafe OAuth2 discovery processing.
An authenticated user with either the mcp:write or a2a:write scope could configure a malicious well-known discovery URL that makes the backend disclose OAuth2 client secrets or another user’s access token to an attacker-controlled endpoint.
AWS said its prior 1.6.1 release prevented internal-address access through this route but did not completely mitigate token disclosure. Version 1.7.0 fully resolves the issue.
The third Loom vulnerability, CVE-2026-103958, is an outbound request handling issue resembling server-side request forgery.
A user with mcp:write or a2a:write permissions could force Loom’s Model Context Protocol tool-server or Agent2Agent remote-agent logic to connect to arbitrary internal destinations and return the responses.
This could expose data from a container credential-vending endpoint, potentially giving attackers temporary AWS credentials. Those credentials could then be used against cloud resources available to the associated IAM role.
AWS also patched CVE-2026-104019, an OS command injection flaw in SageMaker Space startup scripts. The vulnerability results from insufficient sanitization of SageMaker connection details during startup validation.
A project member could potentially craft malicious connection data and execute arbitrary code in another member’s Space.
In projects with Trusted Identity Propagation enabled, a contributor-level user could obtain another member’s temporary execution-role credentials and invoke downstream services on that user’s behalf.
AWS has released fixes in SageMaker Distribution versions 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, and 4.4.3. Version 4.5.x is not affected, while several older affected branches are already out of support.
Mitigation
Organizations should upgrade Loom deployments and patched forks to version 1.7.0 immediately. Before upgrading, AWS advises administrators to configure a Cognito user pool or external identity provider before exposing Loom beyond loopback access and ensure LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV is not enabled in production.
After remediation, organizations should rotate OAuth2 client secrets, revoke and reissue tokens active during the affected period, rotate potentially exposed IAM session credentials, and investigate AWS CloudTrail logs for suspicious activity.
SageMaker Unified Studio users should restart affected Studio Spaces so the globally deployed patched images can take effect.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team
Eswar is a Cyber security content editor with a passion for creating captivating and informative content. With years of experience under his belt in Cyber Security, he is covering Cyber Security News, technology and other news.