TL;DR
AWS published two security bulletins on October 2, 2026, covering four CVEs. Three hit Loom for AWS, an open-source AI agent platform, including an admin takeover bug. The fourth lets a SageMaker Unified Studio project member run code in a teammate’s Space.
- Product: AWS (2 products)
- Vulnerabilities: 4 flaws (CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, CVE-2026-104019)
- Highest severity: 10.0 (Critical · CVSSv4)
- Worst impact: Missing authentication for critical function in for
- Status: No confirmed exploitation yet; patches available
- Action: Update to 1.6.1, 1.7.0, 2.14.12, 3.9.12 (+5) now
| CVE | CVSS (CVSSv4) | Type | Fixed in | Status |
|---|---|---|---|---|
| CVE-2026-103956 | 10 | Missing authentication for critical function in for | 1.6.1 | Not exploited |
| CVE-2026-104019 | 9.3 | OS command injection in the Studio Space startup validation script in Amazon SageMaker Distribution when running on Amazon SageMaker Unified Studio | 2.14.12, 3.9.12, 4.0.11 (+4) | Not exploited |
| CVE-2026-103958 | 8.3 | Server-side request forgery in the tool server and remote agent connection handling in for | 1.7.0 | Not exploited |
| CVE-2026-103957 | 8.2 | Server-side request forgery in the OAuth2 discovery handling in for | 1.7.0 | Not exploited |
Route critical CVEs to one Slack channel, everything else to another.
Try Team free for 14 daysWhy It Matters
Loom for AWS controls AI agents, their tools, and their IAM roles. A takeover there reaches far beyond one app. Similarly, the SageMaker bug could expose another user’s temporary AWS credentials.
AWS rates both bulletins “Important.” Neither bulletin reports exploitation in the wild or a public proof-of-concept.
How the Attacks Work
Loom for AWS
CVE-2026-103956 hits deployments with no identity provider configured. In that setup, AWS says “any network client” could “obtain full administrative authority over the agent control plane.” That includes reading stored credentials and rewriting IAM role policies.
The other two flaws need a user with the mcp:write or a2a:write scope. CVE-2026-103957 abuses OAuth2 discovery to send client secrets or another user’s token to an outside server. Meanwhile, CVE-2026-103958 lets requests reach internal addresses, including the container’s credential endpoint.
SageMaker Unified Studio
CVE-2026-104019 sits in the Space startup script. According to AWS, “improper sanitization of connection details during this validation could allow arbitrary code to be executed in the Space of another project member.” The risk grows when Trusted Identity Propagation is on. There, a project contributor could grab a teammate’s execution role credentials and call AWS services as them.
Affected Versions
- Loom for AWS before 1.7.0 (CVE-2026-103956 was fixed in 1.6.1)
- SageMaker Distribution 2.14.x, 3.9.x, and 4.0.x through 4.4.x before their patched builds
- SageMaker Distribution 2.8-2.13 and 3.3-3.8, which reached end of support and get no fix
Patch and Mitigation Steps
Upgrade Loom for AWS to 1.7.0, as the AWS bulletin on Loom for AWS issues advises. Then rotate OAuth2 client secrets, reissue active tokens, and review CloudTrail.
For SageMaker, AWS deployed the fix globally. Just restart affected Spaces, per the SageMaker Distribution command injection bulletin.
Support Our Threat Intelligence
Find our vulnerability reports and weekly recaps helpful? Support our work today and unlock a 100% ad-free reading experience!