PT-2026-104417 · Unknown · Loom For Aws

CVE-2026-103956

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Loom for AWS versions prior to 1.6.1
Description A missing authentication flaw in the authentication dependency allows remote actors to gain super-admin authority over the agent control plane. This occurs in deployments where no identity provider is configured, enabling unauthorized access via any request to the application API. An attacker can register tool servers, read stored integration credentials, and rewrite the IAM role policies attached to managed agent roles.
Recommendations Upgrade to version 1.6.1 or later.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-103956

Affected Products

Loom For Aws