CVE-2026-103956, CVE-2026-1039... Note

CVE-2026-103956, CVE-2026-103957, and CVE-2026-103958 - Issues in Loom for AWS

AWS has released an important bulletin regarding vulnerabilities in Loom for AWS, an open-source AI agent orchestration platform. Three critical issues have been identified and patched, necessitating an upgrade to version 1.7.0. The first vulnerability, CVE-2026-103956, involved an authentication bypass that allowed any network client administrative control over the agent control plane. This was fixed in version 1.6.1. The second issue, CVE-2026-103957, related to OAuth2 token and credential disclosure. This could occur when an authenticated user configured a specific discovery URL, leading to sensitive information being sent to third-party endpoints. This vulnerability was fully addressed in version 1.7.0. The third vulnerability, CVE-2026-103958, allowed authenticated users to direct connection requests to arbitrary internal network locations. This also included the potential to read responses, including from the container's credential-vending endpoint. This issue was resolved in version 1.7.0 as well. Users are strongly advised to upgrade to the latest version and patch any derivative code. The bulletin highlights the importance of applying these security updates promptly. Further details can be found in the linked article.