AWS Loom 1.7.0 Fixes Authentication and Outbound Request Flaws
Quick Answer
AWS published 2026-124-AWS for Loom for AWS. AWS fixed an authentication bypass, OAuth2 token and secret disclosure, and server-side request forgery with internal response access in Loom for AWS. AWS recommends identity-provider configuration and permission restrictions as interim measures, but directs customers to upgrade to version 1.7.0.
Confirm Scope And Apply The Supported Fix
What to do now: Identify Loom for AWS, match the exact affected release and exposed workflow, apply the supported fix, validate operations, and preserve change and investigation evidence.
Last verified: 2026-10-03 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.
Scope And Authority
| Product scope | Loom for AWS |
|---|---|
| Advisory | 2026-124-AWS |
| CVEs | CVE-2026-103956, CVE-2026-103957, CVE-2026-103958 |
| Authoritative release date | 2026-10-02 19:00:00 UTC (AWS bulletin publication time) |
| Authority revision date | 2026-10-02 19:00:00 UTC (latest authority revision verified for this run) |
| Affected versions | Loom for AWS releases before 1.6.1 for CVE-2026-103956 and releases before 1.7.0 for CVE-2026-103957 and CVE-2026-103958. |
| Fixed version | Loom for AWS 1.7.0 |
| CVSS base score | Not provided by the authority |
| CVSS severity | Not provided by the authority |
| Exploitation status | Not stated by the authority; no exploitation claim is inferred. |
What Changed
AWS fixed an authentication bypass, OAuth2 token and secret disclosure, and server-side request forgery with internal response access in Loom for AWS.
What To Validate Now
- Inventory. Locate Loom for AWS deployments, versions, enabled features, exposure paths, owners, and dependent services.
- Establish applicability. Inventory Loom for AWS deployments and exact versions, identity-provider configuration, principals with mcp:write or a2a:write permissions, connected OAuth providers, and reachable internal services.
- Remediate. Upgrade Loom for AWS to version 1.7.0. As interim controls, configure the identity provider for CVE-2026-103956 and restrict mcp:write and a2a:write permissions for the other two issues. Rotate potentially accessed OAuth secrets and tokens and review CloudTrail.
- Validate. Confirm version 1.7.0, test identity and approved outbound integration flows, verify least-privilege permissions, review CloudTrail and provider logs for unexpected access, rotate exposed credentials where warranted, and retain investigation evidence.
- Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.
Operational Cautions
Preserve CloudTrail and identity-provider evidence before credential rotation, test authentication and integration dependencies, constrain outbound reachability where feasible, and do not infer compromise without supporting telemetry.
Evidence To Retain
- Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
- UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
- Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.
Related TechGeeks Resources
Authoritative References
Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.

