AWS Loom for AWS (2 Oct): CVE-2026-103956 CVSS 10 unauth admin takeover if no IdP; plus SSRF 103957/103958 — patch 1.7.0
AWS Security Bulletin 2026-124-AWS (Important; published 2 October 2026 PDT) covers three issues in Loom for AWS (AWS Labs open-source AI agent orchestration). CVE-2026-103956 (CVSS 4.0 10.0 / CVSS 3.1 10.0 Critical; CWE-306/1188): before 1.6.1, in deployments with no identity provider configured, any network client could obtain full administrative authority over the agent control plane — register tool servers, read stored integration credentials, rewrite IAM role policies on managed agent roles — via any application API request. Fixed in 1.6.1 (released 4 Aug 2026). CVE-2026-103957 (CVSS 4.0 8.2 High): before 1.7.0, authenticated mcp:write/a2a:write users could abuse OAuth2 discovery so the backend sent client secrets or another user’s access token to a third-party endpoint (1.6.1 blocked internal-address reach but not full token disclosure). CVE-2026-103958 (CVSS 4.0 8.3 High): before 1.7.0, same scopes could SSRF connection requests to internal locations including the container credential endpoint and read responses. Upgrade to 1.7.0; until then configure Cognito/external IdP before non-loopback exposure, leave LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV unset in deployed envs, and restrict mcp:write/a2a:write to trusted admins. After upgrade: rotate OAuth2 client secrets, revoke/reissue tokens, and if container role credentials may have been accessed rotate IAM session credentials and review CloudTrail. Acknowledgement: Kenneth Cox. No exploitation claimed in the bulletin. Primary: AWS 2026-124-AWS.
- Product
- Loom for AWS (AWS Labs AI agent orchestration platform)
- Versions
- CVE-2026-103956: < 1.6.1 (fixed 1.6.1). CVE-2026-103957 and CVE-2026-103958: < 1.7.0 (fixed 1.7.0). Recommend 1.7.0+.
- CVSS
- (CVE-2026-103956 CVSS 4.0/3.1 Critical); 8.2 (CVE-2026-103957 CVSS 4.0 High); 8.3 (CVE-2026-103958 CVSS 4.0 High) — Amazon CNA
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H - Exploited in Australia?
- unknown
- Patch to
- Upgrade Loom for AWS to 1.7.0+ (103956 alone was fixed in 1.6.1). Until then: require Cognito/external IdP before non-loopback reachability; unset LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV in deployed environments; restrict mcp:write and a2a:write scopes to trusted admins. After upgrade: rotate OAuth2 client secrets, revoke/reissue access tokens, rotate IAM role session credentials if container credential endpoint may have been hit, review CloudTrail.
Primary: AWS Security Bulletin 2026-124-AWS — Loom for AWS CVE-2026-103956/103957/103958 (2 Oct 2026) · Vendor: AWS — 2026-124-AWS (Loom for AWS) · CVE: CVE-2026-103956, CVE-2026-103957, CVE-2026-103958 · GitHub Advisory GHSA-vgmj-998f-r8mp — Loom CVE-2026-103956
