OFFLINE
Awaiting data
Security intelligence
CriticalCritical vulnerability

CVE-2026-103956 (CVSS 10.0)

NVD · officialPublished Oct 2, 2026Risk 50/100EPSS 0.5%

Missing authentication for critical function in the authentication dependency in Loom for AWS before 1.6.1 allowed remote actors to obtain super-admin authority over the agent control plane, including registering tool servers, reading stored integration credentials, and rewriting the IAM role policies attached to managed agent roles, via any request to the application API in a deployment where no identity provider is configured. To remediate this issue, users should upgrade to version 1.6.1 or later.

CVSS
10.0
AV:NetworkAC:LowPR:NoneUI:None

This record is attributed to NVD. Exploitation status and remediation guidance are kept separate from the vulnerability's technical severity.

Open primary source