AWS Ops Wheel v2 Security Flaws Need Your Attention
AWS Ops Wheel v2 (PR-163 and earlier) has two security issues you should know about. CVE-2026-6911 skips JWT token verification in the v2 API, while CVE-2026-6912 leaves Cognito User Pool attributes too open for writing. If you're running this CloudFormation-deployed tool, update immediately—user action is required.
source: [aws/security-bulletin]