AWS fixes flaws in its Loom agent orchestration platform that could hand attackers full admin control
An authentication bypass and an OAuth2 token leak in Loom, plus a SageMaker command injection bug, are covered in advisories published October 2.

Evidence: Official disclosure. Security stories run only with a named disclosure or independent reporting behind them.
Amazon Web Services has published fixes for three vulnerabilities in Loom for AWS, an open-source AI agent orchestration platform from AWS Labs, and recommends that users upgrade to version 1.7.0 and patch any forked or derived code. The most serious, CVE-2026-103956, affected versions before 1.6.1. In deployments with no identity provider configured, any network client could take full administrative control of the agent control plane. That included registering tool servers, reading stored integration credentials and rewriting IAM role policies attached to managed agent roles. AWS fixed the bug in version 1.6.1, released on August 4. A second flaw, CVE-2026-103957, let an authenticated user with the mcp:write or a2a:write scope point Loom's OAuth2 discovery at a document that sent client secrets, or another user's access token, to an endpoint a third party controls. The bulletin also lists CVE-2026-103958. Cyber Security News reports that AWS also fixed CVE-2026-104019, an OS command injection flaw in the SageMaker Distribution startup process used by Amazon SageMaker Unified Studio. The issues matter because agent control planes hold the credentials and cloud permissions that agents use to act, so a single weak default can expose a whole cloud environment.
Sources
- Amazon Web Services, Inc.CVE-2026-103956, CVE-2026-103957, and CVE-2026-103958 - Issues in Loom for AWS
- Cyber Security NewsAWS Fixes Critical Loom and SageMaker Flaws Enabling Code Execution and Credential Theft