PT-2026-35028 · Unknown · Aws Ops Wheel

Published

2026-04-24

·

Updated

2026-04-24

·

CVE-2026-6912

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions AWS Ops Wheel versions prior to PR #165
Description Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration allows remote authenticated users to escalate to deployment admin privileges. This is achieved via a crafted 'UpdateUserAttributes' API call that sets the custom:deployment admin attribute, enabling the management of Cognito user accounts.
Recommendations Redeploy from the updated repository and ensure any forked or derivative code is patched to incorporate the new fixes.

Fix

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-6912

Affected Products

Aws Ops Wheel