AWS has published two security bulletins on 2 October 2026 detailing four CVEs that affect Loom for AWS and SageMaker Unified Studio. Three flaws hit Loom for AWS, including a critical admin takeover vulnerability, while the fourth could allow a SageMaker Unified Studio Space member to run code in a teammate’s Space. The CVEs are CVE-2026-103956, CVE-2026-103957, CVE-2026-103958, and CVE-2026-104019.
The highest severity is CVSSv4 10.0 for the Loom authentication bypass, with the other Loom and SageMaker flaws rated at CVSSv4 9.3, 8.2–8.3 ranges. AWS notes that none of the bulletins have confirmed exploitation in the wild as of the advisories, but patches are now available.
Affected versions include Loom for AWS before 1.7.0 (with CVE-2026-103956 fixed in 1.6.1) and SageMaker Distribution releases 2.14.x, 3.9.x, and 4.0.x through 4.4.x prior to their patched builds. Older SageMaker branches 2.8–2.13 and 3.3–3.8 reached end of support and will not receive fixes. The Loom issue involves deployments with no identity provider configured (risking full admin control over the agent plane), while CVE-2026-103957 and CVE-2026-103958 relate to OAuth2 discovery and internal credential endpoints.
CVE-2026-104019 concerns an OS command injection risk in the SageMaker Space startup validation script, with greater danger when Trusted Identity Propagation is enabled.
Mitigations call for upgrading Loom for AWS to 1.7.0, rotating OAuth2 client secrets, reissuing tokens, and reviewing CloudTrail; for SageMaker, restart affected Spaces following AWS guidance.