CVE-2026-6912

HIGH

AWS Ops Wheel - Authenticated Privilege Escalation via Cognito User Pool UpdateUserAttributes API

Title source: llm
STIX 2.1

Description

Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165 allows remote authenticated users to escalate to deployment admin privileges and manage Cognito user accounts via a crafted UpdateUserAttributes API call that sets the custom:deployment_admin attribute. To remediate this issue, users should redeploy from the updated repository and ensure any forked or derivative code is patched to incorporate the new fixes.

Scores

CVSS v3 8.8
EPSS 0.0042
EPSS Percentile 34.5%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Details

CWE
CWE-915
Status published
Published Apr 24, 2026
Tracked Since Jun 18, 2026