CVE-2026-6912: Privilege Escalation via Self-Writable Cognito Custom Attribute in AWS Ops Wheel
Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165 allows remote authenticated users to escalate to deployment admin privileges and manage Cognito user accounts via a crafted UpdateUserAttributes API call that sets the custom:deploymentadmin attribute.
To remediate this issue, users should redeploy from the updated repository and ensure any forked or derivative code is patched to incorporate the new fixes.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-6912?
CVE-2026-6912 has been classified as a high severity privilege escalation vulnerability.
How do I fix CVE-2026-6912?
To fix CVE-2026-6912, update your AWS Ops Wheel to the latest version that includes the patch from PR #165.
Who is affected by CVE-2026-6912?
CVE-2026-6912 affects AWS Ops Wheel users with improper access control configurations in Cognito User Pool.
What causes the vulnerability in CVE-2026-6912?
CVE-2026-6912 is caused by improperly controlled modification of dynamically-determined object attributes.
Can I escalate privileges using CVE-2026-6912?
Yes, CVE-2026-6912 allows remote authenticated users to escalate their privileges to deployment admin.