Threat reportCloud SecurityTL-2026-2860
AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal Credentials - CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019
AWS AI Agent Vulnerabilities (Loom, SageMaker Unified (TL-2026-2860), also tracked as GHSA-vgmj-998f-r8mp, is a critical-severity cloud security threat scored CVSS 10, first published 2026-10-03. It has no confirmed attribution, affects AWS Labs Loom for AWS, references 4 CVEs (CVE-2026-103956, CVE-2026-103957, CVE-2026-103958), maps to 8 MITRE ATT&CK techniques (T1059.004, T1078.004, T1098.003), and is covered by 9 detection rules and 6 indicators of compromise.
- CVSS
- 10/10Critical
- CVEs
- 4Referenced vulnerabilities
- Techniques
- 8MITRE ATT&CK
- Actors
- 0Not attributed
- Detection rules
- 9SPL · KQL · Sigma
- IOCs
- 6Indicators of compromise
Key facts for TL-2026-2860
- Threat ID
- TL-2026-2860
- Also known as
- GHSA-vgmj-998f-r8mp, GHSA-jcxf-gpf4-58hm, GHSA-w6g6-h8pv-6mc7, GHSA-w64x-664p-7w66
- Severity
- CRITICAL
- CVSS
- 10 (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H)
- Status
- PATCHED
- Category
- CLOUD
- First published
- Last reviewed
- Attribution confidence
- LOW
- Motivation
- UNKNOWN
- Target sectors
- technology, cloud, artificial-intelligence, data-science
- Target regions
- Global
- Detection rules
- 9
- Indicators of compromise
- 6
How AWS AI Agent Vulnerabilities (Loom, SageMaker Unified works
AWS disclosed on 2026-10-02 four vulnerabilities in the open-source Loom for AWS agent platform and Amazon SageMaker Unified Studio (SageMaker Distribution): unauthenticated super-admin access (CVSS 10.0), OAuth2 secret/token disclosure, SSRF to the container credential endpoint, and cross-user OS command injection (CVSS 9.0). Fixes are available; no in-the-wild exploitation or public PoC is stated.
AWS published security bulletins 2026-124-AWS (Loom for AWS) and 2026-125-AWS (SageMaker Unified Studio) on 2026-10-02, alongside GitHub security advisories in awslabs/loom and aws/sagemaker-distribution.
Loom for AWS (AWS Labs, Apache-2.0) is a platform for building, deploying and operating AI agents on Amazon Bedrock AgentCore Runtime and AWS Strands Agents (Google ADK was added in 1.7.0). Its FastAPI control plane manages agents, memory stores, MCP servers and A2A agent integrations, using Amazon Cognito groups and OAuth2 scopes (mcp:write, a2a:write) for authorization.
CVE-2026-103956 (GHSA-vgmj-998f-r8mp; Critical, CVSS 3.1 10.0, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; CWE-306, CWE-1188; versions before 1.6.1, fixed 1.6.1 released 2026-08-04) is a missing-authentication flaw: the get_current_user dependency in backend/app/dependencies/auth.py unconditionally returned a fixed super-admin identity holding every scope when no Cognito user pool or external identity provider was active, so freshly deployed instances, or ones whose IdP configuration became unavailable, granted any network client full administrative authority. Per the bulletin this lets an attacker register malicious tool servers, read stored integration credentials, modify IAM policies, create/modify/delete all platform resources and invoke any agent. The 1.6.1 fix requires an explicit LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV opt-in and restricts the bypass to loopback clients, failing closed with 401 otherwise. Interim workarounds: configure Cognito/IdP before exposing the backend, keep the flag unset in production and restrict network/security-group access.
CVE-2026-103957 (GHSA-jcxf-gpf4-58hm; CVSS 3.1 6.2 rated Moderate by the GitHub advisory, CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N; CWE-918, CWE-201; before 1.7.0) is unsafe OAuth2 discovery handling: an authenticated user with mcp:write or a2a:write can supply a well-known discovery URL pointing at a third-party server, causing the backend to send a resource's OAuth2 client secret or another user's access token to an attacker-controlled endpoint during MCP-server or A2A-agent connection flows. The backend only checked for public HTTPS targets rather than that the token endpoint matched the deployment's configured identity provider. GBHackers states 1.6.1 blocked internal-address access but did not fully mitigate the disclosure; 1.7.0 (PR #49) requires a deployment-trusted issuer host before any OAuth2 token exchange. Partial workaround: restrict mcp:write/a2a:write to trusted admin groups (g-admins-super, g-admins-demo, g-admins-mcp, g-admins-a2a).
CVE-2026-103958 (GHSA-w6g6-h8pv-6mc7; CVSS 3.1 7.6 High, CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N; CWE-918; before 1.7.0) is SSRF-like outbound request handling in tool-server and remote-agent connections: users with the same scopes can direct backend requests at arbitrary internal network locations and read responses, including the container credential-vending endpoint, exposing temporary AWS credentials. Root cause: no resolved-IP validation and no re-validation of redirect targets. 1.7.0 guards MCP/A2A connection sinks against SSRF via redirect and response-body echo (PR #32) and extends IP-validated, DNS-pinned fetching to all outbound OAuth2/OIDC calls.
CVE-2026-104019 (GHSA-w64x-664p-7w66; Critical, CVSS 3.1 9.0, CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H; OS command injection, CWE-78 by classification of the described flaw) is in the Amazon SageMaker Unified Studio / SageMaker Distribution Space startup script: improper sanitization of connection details during validation (a crafted connection resource property interpolated into a shell command) lets a project contributor or higher execute arbitrary commands in another project member's Space and obtain that member's temporary execution-role credentials; with Trusted Identity Propagation enabled, downstream AWS services can be invoked on the victim's behalf. Affected: 2.8.x-2.13.x and 3.3.x-3.8.x (end of support, no fix), 2.14.x before 2.14.12, 3.9.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, 4.4.x before 4.4.3; 4.5.x and later, and versions before 2.8.0 / 3.3.0, are not affected. No workaround is documented; fixes apply on Space restart.
Loom shipped further hardening after 1.7.0 (per the GitHub release pages): 1.7.1 enforced resource-ownership checks on agent/memory routes and blocked privilege escalation through IdP group mappings; 1.7.2 closed cross-group isolation gaps for roles, authorizers, credentials, MCP servers and A2A agents; 1.7.3 restricted global configuration routes to super-admin and removed settings scopes; 1.7.4 fixed an authorization bypass letting any authenticated user resolve another user's pending human-in-the-loop approval. These indicate that 1.7.0 is the minimum, and the latest 1.7.x is preferable. Note: GitHub release pages render release years as 2024 although they follow the 2026 advisory dates; this report uses the AWS bulletin's 2026 dates.
In-the-wild exploitation, public PoC code and network IOCs are not stated in any source. Credit: Kenneth Cox for coordinated disclosure on the Loom advisories (the GitHub advisory index also lists the handle heeki as credited on the three Loom advisories). Note: the GBHackers article attributes CVE-2026-103958 to bulletin 2026-125; the AWS bulletins show it is in 2026-124 (2026-125 covers only CVE-2026-104019). The bulletins themselves publish no CVSS; scores come from the GitHub advisories.
MITRE ATT&CK techniques used in TL-2026-2860
Execution
T1059.004 Command and Scripting Interpreter: Unix Shell
Initial Access
T1078.004 Valid Accounts: Cloud Accounts; T1190 Exploit Public-Facing Application
Persistence
T1098.003 Account Manipulation: Additional Cloud Roles
Credential Access
T1528 Steal Application Access Token; T1552.005 Unsecured Credentials: Cloud Instance Metadata API; T1555.006 Credentials from Password Stores: Cloud Secrets Management Stores
Lateral Movement
T1550.001 Use Alternate Authentication Material: Application Access Token
Affected products and versions in AWS AI Agent Vulnerabilities (Loom, SageMaker Unified
- AWS Labs — Loom for AWS
Vulnerable versions: < 1.6.1 (CVE-2026-103956); < 1.7.0 (CVE-2026-103957, CVE-2026-103958)
Fixed in: 1.6.1; 1.7.0 - Amazon Web Services — Amazon SageMaker Unified Studio (SageMaker Distribution)
Vulnerable versions: 2.8.x-2.13.x (EOS, no fix); 2.14.x < 2.14.12; 3.3.x-3.8.x (EOS, no fix); 3.9.x < 3.9.12; 4.0.x < 4.0.11; 4.1.x < 4.1.11; 4.2.x < 4.2.8; 4.3.x < 4.3.5; 4.4.x < 4.4.3
Fixed in: 2.14.12; 3.9.12; 4.0.11; 4.1.11; 4.2.8; 4.3.5; 4.4.3
Remediation for AWS AI Agent Vulnerabilities (Loom, SageMaker Unified
Patches
- Loom for AWS 1.6.1 (CVE-2026-103956) and 1.7.0 (CVE-2026-103957, CVE-2026-103958)
- SageMaker Distribution 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, 4.4.3 (4.5.x not affected)
Immediate actions
- Upgrade Loom for AWS to 1.7.0 or later (CVE-2026-103956 is fixed from 1.6.1; the other two need 1.7.0)
- Restart affected SageMaker Unified Studio Spaces so patched SageMaker Distribution versions are applied
- Rotate OAuth2 client secrets and revoke active access tokens issued through Loom
- Revoke and reissue IAM session credentials potentially exposed via Loom or SageMaker Spaces
- Audit CloudTrail logs for suspicious IAM policy changes and credential use
- Restrict network / security-group access to the Loom backend until patched
Workarounds
- Loom: keep LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV unset in production and configure an identity provider
- Loom CVE-2026-103957/103958: restrict mcp:write and a2a:write scopes to trusted administrators (partial)
- SageMaker CVE-2026-104019: none available per AWS
Longer-term hardening
- Configure Amazon Cognito or another external identity provider before exposing Loom beyond local development
- Restrict mcp:write and a2a:write scopes to trusted administrators (g-admins-super, g-admins-demo, g-admins-mcp, g-admins-a2a)
- Migrate SageMaker Distribution 2.8-2.13 and 3.3-3.8 (end of support, no fix) to a supported patched version
- Track later Loom 1.7.x releases (1.7.1-1.7.4) for additional authorization hardening
CVEs associated with AWS AI Agent Vulnerabilities (Loom, SageMaker Unified
CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019
Weaknesses (CWE) in AWS AI Agent Vulnerabilities (Loom, SageMaker Unified
Timeline of AWS AI Agent Vulnerabilities (Loom, SageMaker Unified
- Loom 1.6.0 released (multi-provider LLM support via LiteLLM); the last release line before the authentication-bypass fix
- Loom for AWS 1.6.1 released: local-dev super-admin bypass now requires LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV and loopback clients (CVE-2026-103956); hardened net_guard.py fetcher added for OAuth2/OIDC discovery
- Loom 1.7.0 released: PR #49 requires a deployment-trusted issuer host before OAuth2 token exchange and PR #32 guards MCP/A2A connection sinks against SSRF, closing CVE-2026-103957 and CVE-2026-103958
- Loom 1.7.1-1.7.4 follow-on releases (2026-09-22 to 2026-09-29) harden resource ownership, group isolation and human-in-the-loop approval authorization
- AWS acknowledges Kenneth Cox for coordinated disclosure of the Loom vulnerabilities
- AWS publishes Security Bulletin 2026-125-AWS and GitHub advisory GHSA-w64x-664p-7w66 for SageMaker command injection CVE-2026-104019 (CVSS 9.0); patched Distribution versions 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, 4.4.3 released
- AWS publishes Security Bulletin 2026-124-AWS and GitHub advisories GHSA-vgmj-998f-r8mp, GHSA-jcxf-gpf4-58hm and GHSA-w6g6-h8pv-6mc7 covering CVE-2026-103956, CVE-2026-103957 and CVE-2026-103958
- GBHackers reports the four AWS AI agent vulnerabilities; no in-the-wild exploitation or public PoC is stated
Sources cited for AWS AI Agent Vulnerabilities (Loom, SageMaker Unified
- AWS Security Bulletin 2026-124-AWS (Loom for AWS)
- AWS Security Bulletin 2026-125-AWS (SageMaker Unified Studio, CVE-2026-104019)
- GitHub Advisory GHSA-w64x-664p-7w66 (aws/sagemaker-distribution)
- GitHub Advisory GHSA-vgmj-998f-r8mp (Loom missing authentication, CVE-2026-103956)
- GitHub Advisory GHSA-jcxf-gpf4-58hm (Loom OAuth2 discovery SSRF, CVE-2026-103957)
- GitHub Advisory GHSA-w6g6-h8pv-6mc7 (Loom tool server/remote agent SSRF, CVE-2026-103958)
- Loom v1.6.1 release notes (auth bypass fix, hardened fetcher)
- Loom v1.7.0 release notes (PR #49 issuer validation, PR #32 SSRF sink guard)
- CVE-2026-104019 CVE Record
- CVE-2026-103956 CVE Record
- awslabs/loom - Loom for AWS repository
- AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials (GBHackers)
Detection coverage for TL-2026-2860
As of 2026-10-03, Threadlinqs Intelligence publishes 9 detection rule(s) for TL-2026-2860 across Splunk SPL, Microsoft KQL and Sigma, covering 6 indicator(s) of compromise. The whole corpus is readable without an account; a free account unlocks full detection query text in Splunk SPL, Microsoft KQL and Sigma; paid tiers add raw indicator values, correlation and the MCP server. Threadlinqs MCP server · View plans.