Cyber Security News

AWS Fixes AI Agent Flaws Enabling Authentication Bypass and Credential Theft

AWS released security updates for three vulnerabilities in its open-source Loom platform, used for AI agent orchestration.

These vulnerabilities could allow unauthenticated administrative takeover, disclosure of OAuth2 credentials, and access to internal services. The company strongly urges users to upgrade all Loom deployments and forks to version 1.7.0.

AWS announced these issues in Security Bulletin 2026-124-AWS, published on October 2, 2026. Loom, an AWS Labs project, orchestrates AI agents, tool servers using the Model Context Protocol (MCP), and remote agent connections through agent-to-agent (A2A) integrations.

The identified flaws compromise the critical boundary between the AI-agent control plane and cloud identity infrastructure.

AWS Fixes AI Agent Flaws

The most severe vulnerability, tracked as CVE-2026-103956, is an authentication-bypass flaw affecting Loom versions before 1.6.1.

In deployments without a configured identity provider, any network client could send requests to the application API and gain full administrative access to the agent control plane.

An attacker exploiting this vulnerability could register malicious tool servers, access stored integration credentials, and modify IAM policies associated with managed agent roles.

This flaw is classified under CWE-306 (Missing Authentication for Critical Function) and CWE-1188. AWS addressed this issue in Loom version 1.6.1, released on August 4, 2026.

Until users can complete the upgrade, AWS recommends configuring either an Amazon Cognito user pool or an active external identity provider before exposing the Loom backend beyond loopback.

Organizations should also ensure that `LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV` is not set in any non-development deployment.

AWS also addressed CVE-2026-103957, an OAuth2 discovery-handling flaw that affects Loom versions before 1.7.0. An authenticated user with the `mcp:write` or `a2a:write` scope could configure a malicious well-known discovery URL, causing the backend to transmit OAuth2 client secrets or other users’ access tokens to an attacker-controlled endpoint.

This issue involves server-side request forgery and information exposure vulnerabilities, mapped to CWE-918 and CWE-201. AWS noted that version 1.6.1 blocked internal-address access through this route, but did not completely prevent token disclosure; the full remediation arrived in version 1.7.0.

The third vulnerability, CVE-2026-103958, affects MCP tool-server and A2A remote-agent connection handling in Loom versions before 1.7.0. A user with `mcp:write` or `a2a:write` access could redirect backend connection requests to arbitrary internal network endpoints and read the returned data.

This capability could expose services not available to external attackers, including a container’s credential-vending endpoint. In cloud environments, access to such an endpoint can potentially provide temporary role credentials, turning an application-layer SSRF condition into a broader cloud-account risk. AWS corrected this flaw in Loom version 1.7.0.

AWS also patched CVE-2026-104019, an OS command-injection vulnerability in the Studio Space startup script used by Amazon SageMaker Unified Studio.

The flaw occurs during startup validation, when a SageMaker Space checks the project’s available SageMaker connections. Improper sanitization of connection details could allow arbitrary commands to execute in another project member’s Space.

The attack requires a user with project contributor permissions or higher. In environments where Trusted Identity Propagation is enabled, successful exploitation could allow the attacker to obtain another user’s temporary execution-role credentials and invoke downstream AWS services on that user’s behalf.

AWS stated that it deployed a global fix that sanitizes connection details during the startup-validation process. Patched images are applied to affected Studio Spaces on their next restart, so administrators should restart applicable Spaces promptly.

Stops Cyber threats before impact with 21 min faster MTTR. Integrate ANYRUN’s Sandbox in your SOC.

Divya

Divya is a Senior Journalist at GBhackers covering Cyber Attacks, Threats, Breaches, Vulnerabilities and other happenings in the cyber world.

Recent Posts

Insignary Launches Clarity AIR to Detect Undeclared Open-Source and AI-Written Code

Toronto, Canada, October 8th, 2026, CyberNewswire Insignary Launches Clarity AIR: Closing the Blind Spot Between…

2 hours ago

Hackers Hijack Tensorlake Package to Spread Shai-Hulud Supply Chain Malware

A threat actor published a malicious version of the tensorlake npm package on October 8,…

3 hours ago

PoC Exploit Released for Zammad Vulnerability Enabling Session Hijacking and Remote Code Execution

A proof-of-concept (PoC) exploit has been released for CVE-2026-102489, a critical vulnerability in Zammad that…

4 hours ago

Critical LMCache RCE Vulnerability Remains Unpatched, Public PoC Exploit Available

A critical vulnerability in LMCache allows unauthenticated attackers to execute arbitrary code against reachable multi-process…

4 hours ago

16 Malicious Firefox Extensions Impersonate Crypto Wallets to Steal Seed Phrases and Private Keys

16 malicious Firefox extensions that impersonate cryptocurrency wallets to intercept recovery phrases and private keys…

5 hours ago

Exposed DarkSword iOS Servers Reveal Crypto Wallet Theft From Compromised iPhones

Exposed directories on five servers have revealed an operational DarkSword/Coruna exploitation platform built to compromise…

6 hours ago