AWS Fixes AI Agent Flaws Enabling Authentication Bypass and Credential Theft
AWS patched Loom AI-agent flaws that can bypass authentication, leak OAuth tokens, and expose cloud credentials.
AWS patched four flaws affecting its open-source Loom AI-agent platform and Amazon SageMaker Unified Studio, disclosed in Security Bulletin 2026-124-AWS on October 2, 2026. CVE-2026-103956 let any network client gain full administrative access to Loom deployments before 1.6.1 that had no identity provider. CVE-2026-103957 and CVE-2026-103958, fixed in Loom 1.7.0, let users with mcp:write or a2a:write leak OAuth secrets or tokens and read internal services, including cloud credential endpoints. CVE-2026-104019 is a command-injection bug in SageMaker Studio Space startup that could steal another project member's temporary credentials; patched images apply on restart.
- CVE-2026-103956 allowed unauthenticated admin access when no IdP was configured.
- OAuth token disclosure and internal SSRF were fixed in Loom 1.7.0.
- SSRF could reach a container credential endpoint and yield temporary role credentials.
- SageMaker Studio CVE-2026-104019 is OS command injection between project Spaces.
- AWS urges Loom upgrades to 1.7.0 and prompt Studio Space restarts.
Vulnerabilities mentionedAll →
- CVE-2026-10395610.0<1%Missing authentication in Loom for AWS control planepublished · Loom for AWS PoC
- CVE-2026-1039588.3—Authenticated SSRF in Loom for AWS before 1.7.0
Full article586 words · extracted from gbhackers.com · click to collapse
AWS released security updates for three vulnerabilities in its open-source Loom platform, used for AI agent orchestration.
These vulnerabilities could allow unauthenticated administrative takeover, disclosure of OAuth2 credentials, and access to internal services. The company strongly urges users to upgrade all Loom deployments and forks to version 1.7.0.
AWS announced these issues in Security Bulletin 2026-124-AWS, published on October 2, 2026. Loom, an AWS Labs project, orchestrates AI agents, tool servers using the Model Context Protocol (MCP), and remote agent connections through agent-to-agent (A2A) integrations.
The identified flaws compromise the critical boundary between the AI-agent control plane and cloud identity infrastructure.
AWS Fixes AI Agent Flaws
The most severe vulnerability, tracked as CVE-2026-103956, is an authentication-bypass flaw affecting Loom versions before 1.6.1.
In deployments without a configured identity provider, any network client could send requests to the application API and gain full administrative access to the agent control plane.
An attacker exploiting this vulnerability could register malicious tool servers, access stored integration credentials, and modify IAM policies associated with managed agent roles.
This flaw is classified under CWE-306 (Missing Authentication for Critical Function) and CWE-1188. AWS addressed this issue in Loom version 1.6.1, released on August 4, 2026.
Until users can complete the upgrade, AWS recommends configuring either an Amazon Cognito user pool or an active external identity provider before exposing the Loom backend beyond loopback.
Organizations should also ensure that `LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV` is not set in any non-development deployment.
AWS also addressed CVE-2026-103957, an OAuth2 discovery-handling flaw that affects Loom versions before 1.7.0. An authenticated user with the `mcp:write` or `a2a:write` scope could configure a malicious well-known discovery URL, causing the backend to transmit OAuth2 client secrets or other users’ access tokens to an attacker-controlled endpoint.
This issue involves server-side request forgery and information exposure vulnerabilities, mapped to CWE-918 and CWE-201. AWS noted that version 1.6.1 blocked internal-address access through this route, but did not completely prevent token disclosure; the full remediation arrived in version 1.7.0.
The third vulnerability, CVE-2026-103958, affects MCP tool-server and A2A remote-agent connection handling in Loom versions before 1.7.0. A user with `mcp:write` or `a2a:write` access could redirect backend connection requests to arbitrary internal network endpoints and read the returned data.
This capability could expose services not available to external attackers, including a container’s credential-vending endpoint. In cloud environments, access to such an endpoint can potentially provide temporary role credentials, turning an application-layer SSRF condition into a broader cloud-account risk. AWS corrected this flaw in Loom version 1.7.0.
AWS also patched CVE-2026-104019, an OS command-injection vulnerability in the Studio Space startup script used by Amazon SageMaker Unified Studio.
The flaw occurs during startup validation, when a SageMaker Space checks the project’s available SageMaker connections. Improper sanitization of connection details could allow arbitrary commands to execute in another project member’s Space.
The attack requires a user with project contributor permissions or higher. In environments where Trusted Identity Propagation is enabled, successful exploitation could allow the attacker to obtain another user’s temporary execution-role credentials and invoke downstream AWS services on that user’s behalf.
AWS stated that it deployed a global fix that sanitizes connection details during the startup-validation process. Patched images are applied to affected Studio Spaces on their next restart, so administrators should restart applicable Spaces promptly.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.