AWS Loom for AWS agent orchestration: three CVEs including an authentication bypass, upgrade to 1.7.0
EditorialBy TrustList Editorial
AWS bulletin 2026-124 fixes three flaws in Loom for AWS, its open-source AI agent orchestration platform: an authentication bypass giving full admin control where no identity provider was set, and two credential-leaking request flaws.
- United States
- Seattle, Wa
- Cybersecurity
- Vulnerability Management
- +2 more
About AWS Loom for AWS agent orchestration: three CVEs including an authentication bypass, upgrade to 1.7.0
AWS Loom for AWS agent orchestration: three CVEs including an authentication bypass, upgrade to 1.7.0
2 October 2026 — AWS published security bulletin 2026-124-AWS on 2 October 2026 (12:00 PDT) for Loom for AWS, an open-source AI agent orchestration platform from AWS Labs. It covers three vulnerabilities, all fixed in version 1.7.0. AWS recommends upgrading and patching any forked or derivative code.
Not yet independently verified. Only AWS's own bulletin has been read; no independent report had been found at 2026-10-04. AWS does not say whether any of the flaws has been exploited. We will update this when it can be confirmed, and remove this note.
The three flaws
- CVE-2026-103956, authentication bypass. In versions before 1.6.1, a deployment with no identity provider configured let any network client obtain full administrative authority over the agent control plane. AWS lists what that allowed: registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles. It was fixed in 1.6.1, released on 4 August 2026.
- CVE-2026-103957, OAuth2 token and credential disclosure. In versions before 1.7.0, a signed-in user with the mcp:write or a2a:write scope could set a discovery URL that made the backend send OAuth2 client secrets, or another user's access token, to an endpoint the attacker controls. AWS says 1.6.1 only partly addressed this.
- CVE-2026-103958, outbound request handling. In versions before 1.7.0, the same scopes let a user point tool-server (MCP) or remote-agent (A2A) connections at internal network addresses, including the container's credential-vending endpoint, and read the responses.
Who is affected
Teams that deployed Loom for AWS themselves, and anyone running code forked from it. The first flaw matters most where a deployment was exposed beyond the local machine without Cognito or another identity provider configured. Because the IAM policies of agent roles could be rewritten, the reach of a compromise extends into the AWS account, not only the Loom instance.
What to do
- Upgrade to Loom 1.7.0, and merge the fixes into any fork.
- Until then, follow AWS's workarounds: configure a Cognito user pool or external identity provider before the backend is reachable beyond loopback, make sure LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV is unset outside local development, and restrict the mcp:write and a2a:write scopes to trusted administrators. AWS notes the scope restriction reduces the risk but does not close it.
- Review the IAM policies attached to managed agent roles for changes you did not make.
- Rotate integration credentials and OAuth2 client secrets stored in Loom if a deployment was reachable without an identity provider.
Why it matters for buyers
Agent orchestration platforms hold the credentials for every tool their agents can call. This bulletin shows the two classic failure modes in that design: a control plane left open by default configuration, and outbound connections that can be steered at internal endpoints. Ask the same questions of any agent platform you evaluate.
Sources
- AWS Security Bulletin 2026-124-AWS: Issues in Loom for AWS — 2 October 2026
Categories & features
- United States
- Seattle, Wa
- Cybersecurity
- Vulnerability Management
- Patch Management
- Cloud Security
More on TrustList
Everything here links back to the same verified catalogue. Pick your next stop.
- More United StatesThe ranking for this subject
- CompaniesAgencies, consultancies and IT service providers, ranked by verified reviews.
- ProductsSoftware and SaaS with pricing, features, integrations and alternatives.
- AwardsAnnual recognition decided by verified reviews and an independent jury.
- LaunchesNew products and releases, voted up by the community every day.
- AI ModelsBenchmark scores and community ratings for every major model.
- RequestsBuyers describe what they need; vendors respond directly.
- PeopleReviewers, authors and makers with public profiles.
- ComparePut up to four listings side by side before you shortlist.