AWS Ops Wheel是Amazon Web Services开源的一个支持多租户的随机选择工具。 AWS Ops Wheel存在安全漏洞,该漏洞源于Cognito用户池配置中动态确定对象属性的修改控制不当,可能导致远程经过身份验证的用户通过特制的UpdateUserAttributes API调用提升为部署管理员权限并管理Cognito用户账户。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| AWS | AWS Ops Wheel | 0 ~ 164 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-6911 | 9.8 CRITICAL | Authentication Bypass via Missing JWT Signature Verification in AWS Ops Wheel |
| CVE-2026-6968 | 5.9 MEDIUM | Multiple Path Traversal Variants in awslabs/tough |
| CVE-2026-6967 | 5.9 MEDIUM | Missing Delegated Metadata Validation in awslabs/tough |
| CVE-2026-6966 | 5.3 MEDIUM | Signature Threshold Bypass in awslabs/tough Delegated Roles |
No comments yet