AWS has released security fixes for four vulnerabilities affecting its open-source Loom AI agent orchestration platform and Amazon SageMaker Unified Studio.
The flaws could allow attackers to bypass authentication, steal OAuth2 tokens and temporary cloud credentials, access internal services, and execute arbitrary code in another user’s SageMaker environment.
AWS disclosed the issues in security bulletins published on October 2, 2026. Three flaws affect Loom for AWS, an AWS Labs open-source platform designed to orchestrate AI agents, while the fourth impacts the SageMaker Distribution startup process used by SageMaker Unified Studio.
AWS AI Agent Vulnerabilities
AWS recommends that Loom users upgrade to version 1.7.0 and that SageMaker customers restart affected Studio Spaces to obtain patched images.
The highest-impact Loom flaw, tracked as CVE-2026-103956, affects versions earlier than 1.6.1. It stems from an issue in Loom’s authentication dependency that could let any network client gain complete administrative authority over the agent control plane if a deployment does not have an identity provider configured.
An attacker could use this access to register malicious tool servers, retrieve stored integration credentials, and alter IAM role policies associated with managed agent roles.
AWS classified the issue under CWE-306, Missing Authentication for Critical Function, and CWE-1188, Insecure Default Initialization of Resource Permissions.
AWS fixed CVE-2026-103956 in Loom version 1.6.1, released on August 4, 2026. However, customers should move directly to Loom 1.7.0 because it includes fixes for the additional token-disclosure and internal-network access flaws.
CVE-2026-103957 affects Loom releases before version 1.7.0 and concerns unsafe OAuth2 discovery processing.
An authenticated user with either the mcp:write or a2a:write scope could configure a malicious well-known discovery URL that makes the backend disclose OAuth2 client secrets or another user’s access token to an attacker-controlled endpoint.
AWS said its prior 1.6.1 release prevented internal-address access through this route but did not completely mitigate token disclosure. Version 1.7.0 fully resolves the issue.
The third Loom vulnerability, CVE-2026-103958, is an outbound request handling issue resembling server-side request forgery.
A user with mcp:write or a2a:write permissions could force Loom’s Model Context Protocol tool-server or Agent2Agent remote-agent logic to connect to arbitrary internal destinations and return the responses.
This could expose data from a container credential-vending endpoint, potentially giving attackers temporary AWS credentials. Those credentials could then be used against cloud resources available to the associated IAM role.
AWS also patched CVE-2026-104019, an OS command injection flaw in SageMaker Space startup scripts. The vulnerability results from insufficient sanitization of SageMaker connection details during startup validation.
A project member could potentially craft malicious connection data and execute arbitrary code in another member’s Space.
In projects with Trusted Identity Propagation enabled, a contributor-level user could obtain another member’s temporary execution-role credentials and invoke downstream services on that user’s behalf.
AWS has released fixes in SageMaker Distribution versions 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, and 4.4.3. Version 4.5.x is not affected, while several older affected branches are already out of support.
Mitigation
Organizations should upgrade Loom deployments and patched forks to version 1.7.0 immediately. Before upgrading, AWS advises administrators to configure a Cognito user pool or external identity provider before exposing Loom beyond loopback access and ensure LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV is not enabled in production.
After remediation, organizations should rotate OAuth2 client secrets, revoke and reissue tokens active during the affected period, rotate potentially exposed IAM session credentials, and investigate AWS CloudTrail logs for suspicious activity.
SageMaker Unified Studio users should restart affected Studio Spaces so the globally deployed patched images can take effect.
Join 16,000+ SOC teams using ANY.RUN to streamline threat investigations and reduce manual effort. Explore for your team

