AWS Loom 1.7.0 Fixes Authentication and Outbound Request Flaws

P2 — VALIDATE AND UPDATENot provided by the authority · Not provided by the authorityEXPLOITATION: NOT STATED

Quick Answer

AWS published 2026-124-AWS for Loom for AWS. AWS fixed an authentication bypass, OAuth2 token and secret disclosure, and server-side request forgery with internal response access in Loom for AWS. AWS recommends identity-provider configuration and permission restrictions as interim measures, but directs customers to upgrade to version 1.7.0.

Confirm Scope And Apply The Supported Fix

What to do now: Identify Loom for AWS, match the exact affected release and exposed workflow, apply the supported fix, validate operations, and preserve change and investigation evidence.

Open the authoritative advisory

Last verified: 2026-10-03 UTC. Recheck the authoritative advisory and supported distribution channel before changing production.

Scope And Authority

Product scopeLoom for AWS
Advisory2026-124-AWS
CVEsCVE-2026-103956, CVE-2026-103957, CVE-2026-103958
Authoritative release date2026-10-02 19:00:00 UTC (AWS bulletin publication time)
Authority revision date2026-10-02 19:00:00 UTC (latest authority revision verified for this run)
Affected versionsLoom for AWS releases before 1.6.1 for CVE-2026-103956 and releases before 1.7.0 for CVE-2026-103957 and CVE-2026-103958.
Fixed versionLoom for AWS 1.7.0
CVSS base scoreNot provided by the authority
CVSS severityNot provided by the authority
Exploitation statusNot stated by the authority; no exploitation claim is inferred.

What Changed

AWS fixed an authentication bypass, OAuth2 token and secret disclosure, and server-side request forgery with internal response access in Loom for AWS.

What To Validate Now

  1. Inventory. Locate Loom for AWS deployments, versions, enabled features, exposure paths, owners, and dependent services.
  2. Establish applicability. Inventory Loom for AWS deployments and exact versions, identity-provider configuration, principals with mcp:write or a2a:write permissions, connected OAuth providers, and reachable internal services.
  3. Remediate. Upgrade Loom for AWS to version 1.7.0. As interim controls, configure the identity provider for CVE-2026-103956 and restrict mcp:write and a2a:write permissions for the other two issues. Rotate potentially accessed OAuth secrets and tokens and review CloudTrail.
  4. Validate. Confirm version 1.7.0, test identity and approved outbound integration flows, verify least-privilege permissions, review CloudTrail and provider logs for unexpected access, rotate exposed credentials where warranted, and retain investigation evidence.
  5. Retain evidence. Preserve asset and owner identifiers, the applicability decision, before-and-after versions, change approval, installation output, validation results, and any exception or rollback record.

Operational Cautions

Preserve CloudTrail and identity-provider evidence before credential rotation, test authentication and integration dependencies, constrain outbound reachability where feasible, and do not infer compromise without supporting telemetry.

Evidence To Retain

  • Exact product, release stream, package or application version, enabled feature, environment, and accountable owner.
  • UTC timestamps, authority revision, approved change record, installer or package-manager output, and resulting version.
  • Relevant logs and monitoring evidence, test results, exceptions, compensating controls, and rollback decisions.

Related TechGeeks Resources

Authoritative References

Correction policy: If the authority changes affected versions, fixed versions, severity, exploitation information, mitigations, or required action, TechGeeks will update this notice and its verification date.