AWS Patches Critical Vulnerabilities in Loom AI and SageMaker Platforms
AWS has addressed four security flaws in its open-source Loom AI agent orchestration platform and Amazon SageMaker Unified Studio, which could have enabled attackers to bypass authentication, steal credentials, access internal services, and execute arbitrary code.
The vulnerabilities, disclosed in security bulletins on October 2, 2026, affect Loom for AWS (three flaws) and the SageMaker Distribution startup process (one flaw). AWS has released fixes and urges users to apply updates immediately.
Key Vulnerabilities & Impact
-
CVE-2026-103956 (Loom – Authentication Bypass)
- Affects Loom versions before 1.6.1.
- Exploits a missing authentication check in deployments without an identity provider, allowing attackers to gain full administrative control over the agent control plane.
- Attackers could register malicious tool servers, steal integration credentials, and modify IAM role policies.
- Fixed in Loom 1.6.1 (August 4, 2026), but users should upgrade to 1.7.0 for full protection.
-
CVE-2026-103957 (Loom – OAuth2 Token Disclosure)
- Affects Loom versions before 1.7.0.
- Allows authenticated users with mcp:write or a2a:write permissions to configure a malicious OAuth2 discovery URL, leading to the disclosure of client secrets or access tokens to attacker-controlled endpoints.
- Partially mitigated in 1.6.1, fully resolved in 1.7.0.
-
CVE-2026-103958 (Loom – SSRF-Like Internal Access)
- Affects Loom versions before 1.7.0.
- Enables users with mcp:write or a2a:write permissions to force Loom to connect to arbitrary internal endpoints, potentially exposing temporary AWS credentials via container credential-vending services.
-
CVE-2026-104019 (SageMaker – OS Command Injection)
- Affects SageMaker Distribution startup scripts in versions before 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, and 4.3.5 (4.4.3 and 4.5.x are unaffected).
- Allows a project member to execute arbitrary code in another user’s SageMaker Space, potentially stealing temporary execution-role credentials if Trusted Identity Propagation is enabled.
Mitigation & Remediation
- Loom users should upgrade to version 1.7.0 and configure an identity provider before exposing the platform.
- SageMaker users must restart affected Studio Spaces to apply patched images.
- AWS recommends rotating OAuth2 client secrets, revoking exposed tokens, and reviewing CloudTrail logs for suspicious activity.
The flaws highlight risks in AI agent orchestration and cloud-based development environments, emphasizing the need for prompt patching to prevent credential theft and unauthorized access.
Source: https://gbhackers.com/aws-ai-agent-vulnerabilities/
AWS TPRM report: https://www.rankiteo.com/company/amazon-web-services
"id": "ama1791008649",
"linkid": "amazon-web-services",
"type": "Vulnerability",
"date": "10/2026",
"severity": "85",
"impact": "4",
"explanation": "Attack with significant impact with customers data leaks"
{'affected_entities': [{'industry': 'Cloud Computing/AI',
'name': 'AWS Loom AI',
'type': 'AI Agent Orchestration Platform'},
{'industry': 'Cloud Computing/AI',
'name': 'Amazon SageMaker Unified Studio',
'type': 'Cloud-Based Development Environment'}],
'attack_vector': ['Missing authentication check',
'Malicious OAuth2 discovery URL',
'Forced internal endpoint connections',
'Malicious startup scripts'],
'data_breach': {'sensitivity_of_data': 'High',
'type_of_data_compromised': ['Credentials',
'Tokens',
'Temporary AWS credentials']},
'date_publicly_disclosed': '2026-10-02',
'description': 'AWS has addressed four security flaws in its open-source Loom '
'AI agent orchestration platform and Amazon SageMaker Unified '
'Studio, which could have enabled attackers to bypass '
'authentication, steal credentials, access internal services, '
'and execute arbitrary code.',
'impact': {'data_compromised': ['Integration credentials',
'OAuth2 client secrets',
'Access tokens',
'Temporary AWS credentials',
'Execution-role credentials'],
'identity_theft_risk': ['Personally identifiable information '
'exposure risk'],
'operational_impact': ['Administrative control over agent control '
'plane',
'Unauthorized access to internal services',
'Arbitrary code execution'],
'systems_affected': ['Loom AI agent orchestration platform',
'Amazon SageMaker Unified Studio']},
'lessons_learned': 'The flaws highlight risks in AI agent orchestration and '
'cloud-based development environments, emphasizing the '
'need for prompt patching to prevent credential theft and '
'unauthorized access.',
'post_incident_analysis': {'corrective_actions': ['Patching vulnerabilities',
'Enforcing identity '
'provider usage',
'Restricting internal '
'endpoint access'],
'root_causes': ['Missing authentication checks',
'Insecure OAuth2 configurations',
'Improper input validation in '
'startup scripts']},
'recommendations': ['Upgrade Loom to version 1.7.0',
'Configure an identity provider for Loom',
'Restart affected SageMaker Studio Spaces',
'Rotate OAuth2 client secrets',
'Revoke exposed tokens',
'Review CloudTrail logs for suspicious activity'],
'references': [{'date_accessed': '2026-10-02',
'source': 'AWS Security Bulletins'}],
'response': {'communication_strategy': ['Security bulletins released on '
'October 2, 2026'],
'containment_measures': ['Patching vulnerabilities',
'Rotating OAuth2 client secrets',
'Revoking exposed tokens'],
'enhanced_monitoring': ['Reviewing CloudTrail logs for '
'suspicious activity'],
'remediation_measures': ['Upgrading Loom to version 1.7.0',
'Restarting affected SageMaker Studio '
'Spaces',
'Configuring identity provider for '
'Loom']},
'title': 'AWS Patches Critical Vulnerabilities in Loom AI and SageMaker '
'Platforms',
'type': ['Authentication Bypass',
'OAuth2 Token Disclosure',
'SSRF-Like Internal Access',
'OS Command Injection'],
'vulnerability_exploited': ['CVE-2026-103956',
'CVE-2026-103957',
'CVE-2026-103958',
'CVE-2026-104019']}