# AWS AI Agent Vulnerabilities (Loom, SageMaker Unified Studio) Let Attackers Bypass Authentication and Steal Credentials - CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019

> AWS disclosed on 2026-10-02 four vulnerabilities in the open-source Loom for AWS agent platform and Amazon SageMaker Unified Studio (SageMaker Distribution): unauthenticated super-admin access (CVSS 10.0), OAuth2 secret/token disclosure, SSRF to the container credential endpoint, and cross-user OS command injection (CVSS 9.0). Fixes are available; no in-the-wild exploitation or public PoC is stated.

- **Published:** 2026-10-03T00:00:00Z
- **Last reviewed:** 2026-10-03T00:00:00Z
- **Canonical:** https://intel.threadlinqs.com/threat/TL-2026-2860
- **ID:** TL-2026-2860
- **Severity:** CRITICAL (CVSS 10)
- **Category:** CLOUD
- **Status:** PATCHED
- **Detections:** 9 · **IOCs:** 6 (full data via the Threadlinqs MCP server — Purple tier)
- **CVEs:** CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019

## Description

AWS published security bulletins 2026-124-AWS (Loom for AWS) and 2026-125-AWS (SageMaker Unified Studio) on 2026-10-02, alongside GitHub security advisories in awslabs/loom and aws/sagemaker-distribution.

Loom for AWS (AWS Labs, Apache-2.0) is a platform for building, deploying and operating AI agents on Amazon Bedrock AgentCore Runtime and AWS Strands Agents (Google ADK was added in 1.7.0). Its FastAPI control plane manages agents, memory stores, MCP servers and A2A agent integrations, using Amazon Cognito groups and OAuth2 scopes (mcp:write, a2a:write) for authorization.

CVE-2026-103956 (GHSA-vgmj-998f-r8mp; Critical, CVSS 3.1 10.0, CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H; CWE-306, CWE-1188; versions before 1.6.1, fixed 1.6.1 released 2026-08-04) is a missing-authentication flaw: the get_current_user dependency in backend/app/dependencies/auth.py unconditionally returned a fixed super-admin identity holding every scope when no Cognito user pool or external identity provider was active, so freshly deployed instances, or ones whose IdP configuration became unavailable, granted any network client full administrative authority. Per the bulletin this lets an attacker register malicious tool servers, read stored integration credentials, modify IAM policies, create/modify/delete all platform resources and invoke any agent. The 1.6.1 fix requires an explicit LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV opt-in and restricts the bypass to loopback clients, failing closed with 401 otherwise. Interim workarounds: configure Cognito/IdP before exposing the backend, keep the flag unset in production and restrict network/security-group access.

CVE-2026-103957 (GHSA-jcxf-gpf4-58hm; CVSS 3.1 6.2 rated Moderate by the GitHub advisory, CVSS:3.1/AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:N/A:N; CWE-918, CWE-201; before 1.7.0) is unsafe OAuth2 discovery handling: an authenticated user with mcp:write or a2a:write can supply a well-known discovery URL pointing at a third-party server, causing the backend to send a resource's OAuth2 client secret or another user's access token to an attacker-controlled endpoint during MCP-server or A2A-agent connection flows. The backend only checked for public HTTPS targets rather than that the token endpoint matched the deployment's configured identity provider. GBHackers states 1.6.1 blocked internal-address access but did not fully mitigate the disclosure; 1.7.0 (PR #49) requires a deployment-trusted issuer host before any OAuth2 token exchange. Partial workaround: restrict mcp:write/a2a:write to trusted admin groups (g-admins-super, g-admins-demo, g-admins-mcp, g-admins-a2a).

CVE-2026-103958 (GHSA-w6g6-h8pv-6mc7; CVSS 3.1 7.6 High, CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:C/C:H/I:L/A:N; CWE-918; before 1.7.0) is SSRF-like outbound request handling in tool-server and remote-agent connections: users with the same scopes can direct backend requests at arbitrary internal network locations and read responses, including the container credential-vending endpoint, exposing temporary AWS credentials. Root cause: no resolved-IP validation and no re-validation of redirect targets. 1.7.0 guards MCP/A2A connection sinks against SSRF via redirect and response-body echo (PR #32) and extends IP-validated, DNS-pinned fetching to all outbound OAuth2/OIDC calls.

CVE-2026-104019 (GHSA-w64x-664p-7w66; Critical, CVSS 3.1 9.0, CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:H; OS command injection, CWE-78 by classification of the described flaw) is in the Amazon SageMaker Unified Studio / SageMaker Distribution Space startup script: improper sanitization of connection details during validation (a crafted connection resource property interpolated into a shell command) lets a project contributor or higher execute arbitrary commands in another project member's Space and obtain that member's temporary execution-role credentials; with Trusted Identity Propagation enabled, downstream AWS services can be invoked on the victim's behalf. Affected: 2.8.x-2.13.x and 3.3.x-3.8.x (end of support, no fix), 2.14.x before 2.14.12, 3.9.x before 3.9.12, 4.0.x before 4.0.11, 4.1.x before 4.1.11, 4.2.x before 4.2.8, 4.3.x before 4.3.5, 4.4.x before 4.4.3; 4.5.x and later, and versions before 2.8.0 / 3.3.0, are not affected. No workaround is documented; fixes apply on Space restart.

Loom shipped further hardening after 1.7.0 (per the GitHub release pages): 1.7.1 enforced resource-ownership checks on agent/memory routes and blocked privilege escalation through IdP group mappings; 1.7.2 closed cross-group isolation gaps for roles, authorizers, credentials, MCP servers and A2A agents; 1.7.3 restricted global configuration routes to super-admin and removed settings scopes; 1.7.4 fixed an authorization bypass letting any authenticated user resolve another user's pending human-in-the-loop approval. These indicate that 1.7.0 is the minimum, and the latest 1.7.x is preferable. Note: GitHub release pages render release years as 2024 although they follow the 2026 advisory dates; this report uses the AWS bulletin's 2026 dates.

In-the-wild exploitation, public PoC code and network IOCs are not stated in any source. Credit: Kenneth Cox for coordinated disclosure on the Loom advisories (the GitHub advisory index also lists the handle heeki as credited on the three Loom advisories). Note: the GBHackers article attributes CVE-2026-103958 to bulletin 2026-125; the AWS bulletins show it is in 2026-124 (2026-125 covers only CVE-2026-104019). The bulletins themselves publish no CVSS; scores come from the GitHub advisories.

## MITRE ATT&CK

- T1190 Exploit Public-Facing Application
- T1078.004 Valid Accounts: Cloud Accounts
- T1059.004 Command and Scripting Interpreter: Unix Shell
- T1098.003 Account Manipulation: Additional Cloud Roles
- T1528 Steal Application Access Token
- T1552.005 Unsecured Credentials: Cloud Instance Metadata API
- T1555.006 Credentials from Password Stores: Cloud Secrets Management Stores
- T1550.001 Use Alternate Authentication Material: Application Access Token

## Sources

- [AWS Security Bulletin 2026-124-AWS (Loom for AWS)](https://aws.amazon.com/security/security-bulletins/2026-124-aws/)
- [AWS Security Bulletin 2026-125-AWS (SageMaker Unified Studio, CVE-2026-104019)](https://aws.amazon.com/security/security-bulletins/2026-125-aws/)
- [GitHub Advisory GHSA-w64x-664p-7w66 (aws/sagemaker-distribution)](https://github.com/aws/sagemaker-distribution/security/advisories/GHSA-w64x-664p-7w66)
- [GitHub Advisory GHSA-vgmj-998f-r8mp (Loom missing authentication, CVE-2026-103956)](https://github.com/awslabs/loom/security/advisories/GHSA-vgmj-998f-r8mp)
- [GitHub Advisory GHSA-jcxf-gpf4-58hm (Loom OAuth2 discovery SSRF, CVE-2026-103957)](https://github.com/awslabs/loom/security/advisories/GHSA-jcxf-gpf4-58hm)
- [GitHub Advisory GHSA-w6g6-h8pv-6mc7 (Loom tool server/remote agent SSRF, CVE-2026-103958)](https://github.com/awslabs/loom/security/advisories/GHSA-w6g6-h8pv-6mc7)
- [Loom v1.6.1 release notes (auth bypass fix, hardened fetcher)](https://github.com/awslabs/loom/releases/tag/v1.6.1)
- [Loom v1.7.0 release notes (PR #49 issuer validation, PR #32 SSRF sink guard)](https://github.com/awslabs/loom/releases/tag/v1.7.0)
- [CVE-2026-104019 CVE Record](https://www.cve.org/CVERecord?id=CVE-2026-104019)
- [CVE-2026-103956 CVE Record](https://www.cve.org/CVERecord?id=CVE-2026-103956)
- [awslabs/loom - Loom for AWS repository](https://github.com/awslabs/loom)
- [AWS AI Agent Vulnerabilities Let Attackers Bypass Authentication and Steal Credentials (GBHackers)](https://gbhackers.com/aws-ai-agent-vulnerabilities/)

## Full data

Detection queries (Splunk SPL / Microsoft KQL / Sigma) and IOC values require the Threadlinqs MCP server (Purple tier): https://intel.threadlinqs.com/mcp

Canonical: https://intel.threadlinqs.com/threat/TL-2026-2860
