CVE-2026-103956: Loom for AWS unauthenticated super-admin
Loom for AWS before 1.6.1 grants every request t-admin / g-admins-super when Cognito is unset and no external IdP is active, including requests with no Authorization header. A fresh deploy is an open admin panel. Labbed on v1.6.0 against v1.6.1. Unauthenticated GET /api/auth/me returns local-dev. Unauthenticated MCP register plus export returns the planted OAuth secret.