Skip to content
Rush Commerce
AI & Automation3 min read

AWS Loom CVE-2026-103956: no identity provider, no auth

AWS disclosed a missing-auth flaw in Loom, its open-source AI agent control plane: with no identity provider set, any client got super-admin. Upgrade to 1.7.0.

Agent platforms hold the keys to everything your agents touch. AWS Loom CVE-2026-103956 shows what happens when the default is open. Loom is an AWS Labs open-source platform for orchestrating AI agents, their tool servers, and their IAM roles. Before version 1.6.1, if you deployed it without an identity provider, its API didn't check who was calling. Any network client got super-admin.

What actually happened

AWS published security bulletin 2026-124-AWS on October 2 covering three Loom CVEs:

  • CVE-2026-103956: missing authentication on the application API when no identity provider is configured. An unauthenticated caller could register tool servers, read stored integration credentials, and rewrite the IAM role policies attached to managed agent roles. Fixed in 1.6.1, released August 4. Public CVE listings score it CVSS 10.0.
  • CVE-2026-103957: an authenticated user could point OAuth2 discovery at a malicious URL and leak client secrets and tokens to a third party. Fixed in 1.7.0.
  • CVE-2026-103958: an authenticated user could aim tool-server and agent connections at internal addresses and read the responses, credential endpoints included. Fixed in 1.7.0.

AWS's instructions: upgrade to 1.7.0, rotate OAuth2 client secrets, revoke and reissue tokens from the affected period, and if credentials were accessed, rotate IAM role credentials and review CloudTrail. The same day, AWS also fixed a command injection in SageMaker Unified Studio Space startup validation (bulletin 2026-125-AWS).

Why it matters for your business

The bug is "missing auth," but the lesson is about defaults. Someone stands up an agent platform for a demo, skips the identity provider because it's "internal," and that demo becomes production. Now one open port gives an outsider the power to edit IAM policies. That's not an agent compromise. That's an AWS account compromise.

Find every agent control plane you run. Loom, LangGraph servers, MCP gateways, homegrown dashboards. If it can attach tools or assume roles, it's tier-zero infrastructure.

No identity provider means no deploy. Make IdP config a hard requirement in your infrastructure code, not a setup checklist item someone skips.

Scope the roles agents can touch. If your control plane can rewrite IAM policies at all, a bug turns into full account takeover. Use permission boundaries so even a super-admin on the agent platform can't grant past them.

Key takeaways

  • Loom for AWS before 1.6.1 skipped authentication entirely when no identity provider was configured
  • Impact: register tool servers, read stored credentials, rewrite IAM role policies on agent roles
  • Two more Loom CVEs (OAuth2 secret leak and internal request forgery) are fixed only in 1.7.0
  • AWS says upgrade to 1.7.0, rotate OAuth2 secrets and tokens, and check CloudTrail
  • Treat agent control planes as tier-zero; enforce IdP config and IAM permission boundaries in code

Running agents with real cloud permissions? We build agent systems with identity enforced at deploy time and IAM boundaries the agent can't cross. See how we build agents, or have us review your setup.

Sources: AWS Security Bulletin 2026-124-AWS, AWS Security Bulletin 2026-125-AWS, Strix CVE record.

  • #aws
  • #loom
  • #cve-2026-103956
  • #ai-agents
  • #agent-security
TR

Tommy Rush — Founder, Rush Commerce

Operator turned builder. 15+ years running operations — now shipping the systems businesses run on. More

Get The Rush Report weekly — one email, zero fluff.