bartek@aws: ~/news
$ whoami
$ AWS Architect · DevOps · Cloud
Friday, October 2, 2026

Loom for AWS Patches Three Critical Security Flaws

Loom for AWS has three nasty vulnerabilities that need your attention. CVE-2026-103956 lets unauthenticated attackers grab full admin access when no identity provider is set up. CVE-2026-103957 and CVE-2026-103958 allow authenticated users to leak OAuth2 tokens and credentials through misconfigured discovery endpoints. Upgrade to version 1.7.0 immediately—this is a must-do, not optional.

source: [aws/security-bulletin]