PT-2026-104417 · Unknown · Loom For Aws
CVE-2026-103956
·
Published
2026-10-02
·
Updated
2026-10-02
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Loom for AWS versions prior to 1.6.1
Description
A missing authentication flaw in the authentication dependency allows remote actors to gain super-admin authority over the agent control plane. This occurs in deployments where no identity provider is configured, enabling unauthorized access via any request to the application API. An attacker can register tool servers, read stored integration credentials, and rewrite the IAM role policies attached to managed agent roles.
Recommendations
Upgrade to version 1.6.1 or later.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Loom For Aws