criticalresolved

Loom for AWS unauthenticated admin access (CVE-2026-103956)

Loom for AWS exposed a fixed super-admin identity when no Amazon Cognito user pool or external identity provider was configured. A network client could then read, create, modify, or delete platform resources without credentials.

The vulnerable authentication dependency returned the fixed t-admin/g-admins-super identity when an instance had no configured active identity provider. That state can exist before identity setup is completed or when configuration is unavailable, so a reachable backend accepted unauthenticated requests with super-admin privileges.

AWS Labs fixed the issue in Loom 1.6.1. The GitHub security advisory assigns CVE-2026-103956 a CVSS 3.1 score of 10.0 and says deployments must explicitly opt in to local unauthenticated development, restricted to loopback requests.

Takeaway

Upgrade to Loom 1.6.1 or later and verify that every non-local deployment has an active identity provider. Do not expose the backend until unauthenticated local-development mode is disabled and network reachability is restricted.

Sources

mcploom-for-awsCVE-2026-103956