Loom for AWS Patches Three Critical Security Flaws
Loom for AWS has three nasty vulnerabilities that need your attention. CVE-2026-103956 lets unauthenticated attackers grab full admin access when no identity provider is set up. CVE-2026-103957 and CVE-2026-103958 allow authenticated users to leak OAuth2 tokens and credentials through misconfigured discovery endpoints. Upgrade to version 1.7.0 immediately—this is a must-do, not optional.
source: [aws/security-bulletin]