HomeCyber BalkansAWS AI Agent Vulnerabilities Allow Attackers to Bypass Authentication and Steal Credentials

AWS AI Agent Vulnerabilities Allow Attackers to Bypass Authentication and Steal Credentials

Published on

spot_img

AWS (Amazon Web Services) has recently announced critical security fixes addressing vulnerabilities identified within its open-source Loom AI agent orchestration platform, as well as the Amazon SageMaker Unified Studio. These flaws, if exploited, could potentially allow malicious actors to bypass authentication mechanisms, exfiltrate OAuth2 tokens and temporary cloud credentials, access internal services, and execute arbitrary code within another user’s SageMaker environment.

The issues were publicly disclosed through security bulletins on October 2, 2026, marking an urgent call for action from AWS to its user community. Specifically, three vulnerabilities were found to impact Loom for AWS—a dedicated open-source platform created by AWS Labs that orchestrates AI agents—while the fourth vulnerability pertains to the SageMaker Distribution startup process utilized by SageMaker Unified Studio.

AWS AI Agent Vulnerabilities

In light of these findings, AWS has recommended that all Loom users upgrade to version 1.7.0. SageMaker users are advised to restart any affected Studio Spaces to ensure that the patched images are deployed correctly.

Among the most concerning of these vulnerabilities is CVE-2026-103956, which affects all Loom versions prior to 1.6.1. This flaw is traced back to a vulnerability within Loom’s authentication dependency, potentially allowing any network client to gain administrative control over the agent control plane—particularly if a deployment fails to configure an identity provider. Such access could facilitate malicious registration of tool servers, retrieval of stored integration credentials, and alterations of IAM (Identity and Access Management) role policies linked with managed agent roles.

AWS categorizes this issue under two specific weaknesses: CWE-306, which pertains to "Missing Authentication for Critical Function," and CWE-1188, which concerns the "Insecure Default Initialization of Resource Permissions." While AWS addressed CVE-2026-103956 in the Loom version 1.6.1, released on August 4, 2026, users are encouraged to upgrade directly to Loom 1.7.0, as it integrates solutions for further issues related to token disclosure and internal network access.

Another vulnerability, CVE-2026-103957, affects all Loom releases predating version 1.7.0 and is linked to unsafe OAuth2 discovery processing. An authenticated user with either the mcp:write or a2a:write scope can maliciously configure a discovery URL causing the backend to disclose OAuth2 client secrets or access tokens belonging to other users to an attacker-controlled endpoint. AWS has confirmed that while version 1.6.1 mitigated internal address access through this pathway, it did not completely resolve the token disclosure issue. Version 1.7.0 has addressed these concerns fully.

The third vulnerability within Loom, known as CVE-2026-103958, presents an outbound request handling issue that bears resemblance to a server-side request forgery. Users endowed with either mcp:write or a2a:write permissions may potentially compel Loom’s Model Context Protocol tool-server or Agent2Agent remote-agent logic to connect with arbitrary internal destinations and return responses. This action could inadvertently expose sensitive data from a container credential-vending endpoint, giving attackers access to temporary AWS credentials linked to the respective IAM role.

In addition to the Loom vulnerabilities, AWS also patched CVE-2026-104019, which is characterized as an OS command injection vulnerability within SageMaker Space startup scripts. This particular flaw arises from inadequate sanitization of SageMaker connection details during the validation phase of startup. It poses a risk whereby a project member could design malicious connection data to execute arbitrary code within another participant’s Space. Contributors with Trusted Identity Propagation enabled could potentially exploit this vulnerability to obtain another participant’s temporary execution-role credentials, thus invoking downstream services on their behalf.

AWS has rolled out fixes across various SageMaker Distribution versions, including 2.14.12, 3.9.12, 4.0.11, 4.1.11, 4.2.8, 4.3.5, and 4.4.3. It is important to note that version 4.5.x is not impacted, while several older branches that are affected are already past their support lifecycle.

Mitigation

Organizations leveraging Loom should urgently upgrade their deployments and patched forks to version 1.7.0. AWS strongly advises administrators to configure a Cognito user pool or to utilize an external identity provider prior to exposing Loom to any network access beyond loopback functionality. Additionally, it’s imperative to ensure that the environment variable LOOM_ALLOW_UNAUTHENTICATED_LOCAL_DEV is not enabled in production setups.

After applying these fixes, it is crucial for organizations to rotate OAuth2 client secrets, revoke and reissue any active tokens from the affected timeline, and rotate potentially exposed IAM session credentials. It is also advisable to analyze AWS CloudTrail logs for any suspicious activity that could suggest misuse of these vulnerabilities.

For users of SageMaker Unified Studio, restarting the compromised Studio Spaces will be necessary to enable the incorporation of the globally deployed patched images effectively. These security updates underscore the importance of ongoing vigilance and proactive measures in safeguarding cloud environments, particularly as vulnerabilities continue to emerge in complex platforms like AWS.

Source link

Latest articles

Shadow AI Governance Creates Security Gaps

In recent years, the rise of generative artificial intelligence (AI) tools has led employees...

Critical GitLab AI Gateway Vulnerability Allows Attackers to Execute Arbitrary Commands

GitLab has recently unveiled urgent security updates addressing a significant flaw in its Self-Hosted...

Healthcare Providers Reach Settlement in Pixel Tracking Lawsuits

Healthcare Providers Settle Lawsuits Over Improper Patient Data Sharing In a significant legal development, two...

Microsoft Alerts on ClickFix Attacks Using Fake CAPTCHA Lures for Malicious Command Execution

Microsoft Alerts Public to ClickFix Attacks Utilizing Fake CAPTCHA Prompts In a recent announcement, Microsoft...

More like this

Shadow AI Governance Creates Security Gaps

In recent years, the rise of generative artificial intelligence (AI) tools has led employees...

Critical GitLab AI Gateway Vulnerability Allows Attackers to Execute Arbitrary Commands

GitLab has recently unveiled urgent security updates addressing a significant flaw in its Self-Hosted...

Healthcare Providers Reach Settlement in Pixel Tracking Lawsuits

Healthcare Providers Settle Lawsuits Over Improper Patient Data Sharing In a significant legal development, two...