CVE-2026-6912
HIGHAWS Ops Wheel - Authenticated Privilege Escalation via Cognito User Pool UpdateUserAttributes API
Title source: llmDescription
Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165 allows remote authenticated users to escalate to deployment admin privileges and manage Cognito user accounts via a crafted UpdateUserAttributes API call that sets the custom:deployment_admin attribute. To remediate this issue, users should redeploy from the updated repository and ensure any forked or derivative code is patched to incorporate the new fixes.
References (3)
Core 3
Core References
Various Sources
https://aws.amazon.com/security/security-bulletins/2026-018-aws/
Issue Tracking
https://github.com/aws/aws-ops-wheel/pull/165
Scores
CVSS v3
8.8
EPSS
0.0042
EPSS Percentile
34.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Details
CWE
CWE-915
Status
published
Published
Apr 24, 2026
Tracked Since
Jun 18, 2026