Skip to content
AWS Fixes AI Agent Flaws Enabling Authentication Bypass and Credential Theft

AWS Fixes AI Agent Flaws Enabling Authentication Bypass and Credential Theft

Gbhackers • October 5, 2026

AWS released security updates for three vulnerabilities in its open-source Loom platform, used for AI agent orchestration.

These vulnerabilities could allow unauthenticated administrative takeover, disclosure of OAuth2 credentials, and access to internal services. The company strongly urges users to upgrade all Loom deployments and forks to version 1.7.0.

AWS announced these issues in Security Bulletin 2026-124-AWS, published on October 2, 2026. Loom, an AWS Labs project, orchestrates AI agents, tool servers using the Model Context Protocol (MCP) , and remote agent connections through agent-to-agent (A2A) integrations.

The identified flaws compromise the critical boundary between the AI-agent control plane and cloud identity infrastructure.

AWS Fixes AI Agent Flaws

The most severe vulnerability, tracked as CVE-2026-103956, is an authentication-bypass flaw affecting Loom versions before 1.6.1.

In deployments without a configured identity provider, any network client could send requests to the application API and gain full administrative access to the agent control plane.

An attacker exploiting this vulnerability could register malicious tool servers, access stored integration credentials, and modify IAM policies associated with managed agent roles.

This flaw is classified under CWE-306 (Missing Authentication for Critical Function) and CWE-1188. AWS addressed this issue in Loom version 1.6.1, released on August 4, 2026.

Until users can complete the upgrade, AWS recommends configuring either an Amazon Cognito user pool or an active external identity provider before exposing the Loom backend beyond loopback.

Organizations should also ensure that `LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV` is not set in any non-development deployment.

AWS also addressed CVE-2026-103957, an OAuth2 discovery-handling flaw that affects Loom versions before 1.7.0. An authenticated user with the `mcp:write` or `a2a:write` scope could configure a malicious well-known discovery URL, causing the backend to transmit OAuth2 client secrets or other users’ access tokens to an attacker-controlled endpoint.

This issue involves server-side request forgery and information exposure vulnerabilities, mapped to CWE-918 and CWE-201. AWS noted that version 1.6.1 blocked internal-address access through this route, but did not completely prevent token disclosure; the full remediation arrived in version 1.7.0.

The third vulnerability, CVE-2026-103958, affects MCP tool-server and A2A remote-agent connection handling in Loom versions before 1.7.0. A user with `mcp:write` or `a2a:write` access could redirect backend connection requests to arbitrary internal network endpoints and read the returned data.

This capability could expose services not available to external attackers, including a container’s credential-vending endpoint. In cloud environments, access to such an endpoint can potentially provide temporary role credentials, turning an application-layer SSRF condition into a broader cloud-account risk. AWS corrected this flaw in Loom version 1.7.0.

AWS also patched CVE-2026-104019, an OS command-injection vulnerability in the Studio Space startup script used by Amazon SageMaker Unified Studio.

The flaw occurs during startup validation, when a SageMaker Space checks the project’s available SageMaker connections. Improper sanitization of connection details could allow arbitrary commands to execute in another project member’s Space.

The attack requires a user with project contributor permissions or higher. In environments where Trusted Identity Propagation is enabled, successful exploitation could allow the attacker to obtain another user’s temporary execution-role credentials and invoke downstream AWS services on that user’s behalf.

AWS stated that it deployed a global fix that sanitizes connection details during the startup-validation process. Patched images are applied to affected Studio Spaces on their restart, so administrators should restart applicable Spaces promptly.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC .

Artificial Intelligence

Cyber security Course

Cyber Security Resources

Cybersecurity

Information Gathering

Information Security Risks

New RemoveMacAI Tool Removes Apple Intelligence Models and Reclaims Mac Storage

Apple Strengthens macOS Privacy Controls as AI Agents Become More Autonomous

Google Gemini to Gain Full Computer Access With New Permission

Critical libheif Vulnerability Could Enable Remote Code Execution Through WordPress Image Uploads

Japanese Police Impersonation Scam Operation Dismantled as 16 Suspects Detained in Timor-Leste

Denmark Confirms Major Security Incident Exposing 8.8 Million Citizen Records