CVE-2026-103956

Source
https://cve.org/CVERecord?id=CVE-2026-103956
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103956.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-103956
Aliases
  • GHSA-vgmj-998f-r8mp
Published
2026-10-02T19:06:06Z
Modified
2026-10-04T02:46:30Z
Severity
  • 10.0 (Critical) CVSS_V4 - CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H CVSS Calculator
Summary
Missing authentication for critical function in Loom for AWS
Details

Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to the application API in a deployment where no identity provider is configured.

To remediate this issue, users should upgrade to version 1.6.1 or later.

Database specific
{
    "cna_assigner":  "AMZN",
    "cwe_ids":  [
        "CWE-1188",
        "CWE-306"
    ],
    "osv_generated_from":  "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/103xxx/CVE-2026-103956.json"
}
References

Affected packages

Git / github.com/awslabs/loom

Affected ranges

Type
GIT
Repo
https://github.com/awslabs/loom
Events
Introduced
0 Unknown introduced commit / All previous commits are affected
Fixed
Database specific
Show details
{
    "extracted_events":  [
        {
            "introduced":  "0"
        },
        {
            "fixed":  "1.6.1"
        }
    ],
    "source":  [
        "AFFECTED_FIELD",
        "DESCRIPTION",
        "REFERENCES"
    ]
}

Affected versions

v1.*
v1.6.0

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-103956.json"