Complete AI Training

AI news ·

AWS fixes authentication bypass and token theft flaws in Loom and SageMaker

AWS disclosed four vulnerabilities in its Loom AI agent platform and SageMaker Unified Studio, including a flaw letting unauthenticated attackers seize full administrative control.

Share

AWS disclosed and patched four security vulnerabilities on October 2, 2026, affecting its Loom AI agent orchestration platform and Amazon SageMaker Unified Studio. The most severe flaw allows unauthenticated attackers to seize full administrative control of a Loom deployment, exposing cloud credentials and enabling arbitrary code execution in downstream environments.

Loom authentication bypass opens the door to full control

The critical vulnerability, tracked as CVE-2026-103956, affects Loom versions earlier than 1.6.1. It stems from a missing authentication check in Loom's dependency chain. When a deployment runs without a configured identity provider, any network client can obtain administrative access to the agent control plane.

An attacker exploiting this flaw could register malicious tool servers, extract stored integration credentials, and modify IAM role policies attached to managed agent roles. The vulnerability carries a CWE-306 classification for missing authentication on critical functions, along with CWE-1188 for insecure default resource permissions. AWS fixed it in version 1.6.1, released August 4, 2026, but organizations should move directly to version 1.7.0.

OAuth2 token theft and internal network access

Two additional Loom flaws required the 1.7.0 release. CVE-2026-103957 involves unsafe handling of OAuth2 discovery URLs. An authenticated user with mcp:write or a2a:write scope could configure a malicious well-known discovery endpoint. The Loom backend would then send OAuth2 client secrets or another user's access token to an attacker-controlled server. AWS said the earlier 1.6.1 patch blocked internal address access in this code path but did not fully stop token disclosure.

CVE-2026-103958 is a server-side request forgery flaw in Loom's Model Context Protocol tool server and Agent2Agent remote agent connection logic. A user with write permissions could force the platform to connect to arbitrary internal network destinations and return their responses. This includes container credential-vending endpoints, potentially exposing temporary AWS credentials that grant access to cloud resources within the affected role's permissions.

SageMaker command injection risk

The fourth issue, CVE-2026-104019, is an OS command injection vulnerability in SageMaker Space startup scripts used by Amazon SageMaker Unified Studio. The flaw arises from improper sanitization of connection details during startup validation. A project member could craft connection information that executes arbitrary code inside another member's SageMaker Space. In projects using Trusted Identity Propagation, this could let a contributor-level user obtain another member's temporary execution-role credentials and invoke downstream AWS services on their behalf.

Fixed versions for SageMaker Distribution include 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, and 4.4.3. Version 4.5.x is unaffected. AWS recommends restarting affected Studio Spaces to receive updated images.

Mitigation steps for affected organizations

Organizations running Loom should upgrade to version 1.7.0 and patch any forks or derivative deployments. Until patching is complete, AWS recommends requiring a Cognito user pool or active external identity provider before exposing Loom beyond loopback access. The LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV flag must not be set in production environments.

Access to the mcp:write and a2a:write scopes should be limited to trusted administrators. After upgrading, teams should rotate OAuth2 client secrets, revoke and reissue access tokens active during the exposure window, rotate any potentially accessed IAM role session credentials, and review AWS CloudTrail logs for suspicious activity.

These vulnerabilities sit at the intersection of identity governance and cloud infrastructure control. The Loom authentication bypass means an unauthenticated attacker could gain administrative access to an AI agent platform that holds integration credentials and IAM role policies. For regulated sectors, that represents a direct path to unauthorized cloud resource access and potential data exposure. The SageMaker command injection flaw compounds the risk by enabling cross-user credential theft in collaborative data science environments. Audit teams should verify that Loom deployments are patched to version 1.7.0, confirm identity provider configuration is enforced, and review CloudTrail logs for the period before patching. The exposure window for the critical authentication bypass extends from initial deployment through August 2026 for organizations that did not configure an external identity provider.

Share