AWS Patches Four Loom and SageMaker Credential Flaws
AWS fixed four Loom and SageMaker flaws disclosed October 2, 2026, that can bypass auth, leak tokens, and steal credentials.
AWS patched four vulnerabilities in the open-source Loom AI agent platform and Amazon SageMaker Unified Studio, disclosed on October 2, 2026. The later report identifies the notice as Security Bulletin 2026-124-AWS, which the earlier report does not name. CVE-2026-103956 can give any network client full administrative control of Loom when no identity provider is configured; the October 5 report says affected deployments were those before 1.6.1, a version cutoff absent from the earlier report. CVE-2026-103957 and CVE-2026-103958, fixed in Loom 1.7.0, let users with mcp:write or a2a:write leak OAuth2 secrets or tokens and reach internal services, including credential endpoints that may yield temporary AWS role credentials. CVE-2026-104019 is command injection in SageMaker Studio Space startup scripts that can run code in another project member's environment and steal temporary role credentials, with patched images applying after a restart. Both reports agree on the four CVE IDs and recommend upgrading Loom to 1.7.0 and restarting Studio Spaces.
- Four flaws in open-source Loom and Amazon SageMaker Unified Studio were disclosed on October 2, 2026; the later report cites Security Bulletin 2026-124-AWS.
- CVE-2026-103956 can give any network client full Loom admin access when no identity provider is configured; the October 5 report says this applied to deployments before 1.6.1.
- CVE-2026-103957, fixed in Loom 1.7.0, lets users with mcp:write or a2a:write leak OAuth2 secrets or access tokens.
- CVE-2026-103958, also fixed in Loom 1.7.0, is SSRF that can reach internal services, including a container credential endpoint, and expose temporary AWS role credentials.
- CVE-2026-104019 is OS command injection in SageMaker Studio Space startup scripts that can run in another project member's environment and steal temporary role credentials.
- AWS urges upgrading Loom to 1.7.0 and restarting Studio Spaces so patched images apply.
Coverage timelineoldest first · each row is one article
- · 5d agoAWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials
GBHackers· 74
AWS patched four Loom and SageMaker flaws enabling auth bypass, token theft, SSRF, and cross-user command execution.
- · 3d agoAWS Fixes AI Agent Flaws Enabling Authentication Bypass and Credential Theft
GBHackers· 68
AWS patched Loom AI-agent flaws that can bypass authentication, leak OAuth tokens, and expose cloud credentials.
Vulnerabilities in this storyAll →
- CVE-2026-10395610.0<1%Missing authentication in Loom for AWS control planepublished · Loom for AWS PoC
- CVE-2026-1039588.3—Authenticated SSRF in Loom for AWS before 1.7.0