HarborGuard / CVE
Back to search
CRITICALCVE-2026-6911Published Modified CNA AMZN

CVE-2026-6911: Authentication Bypass via Missing JWT Signature Verification in AWS Ops Wheel

Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to the application, including the ability to read, modify, and delete all application data across tenants and manage Cognito user accounts within the deployment's User Pool, via a crafted JWT sent to the API Gateway endpoint. To remediate this issue, users should redeploy from the updated repository and ensure any forked or derivative code is patched to incorporate the new fixes.

Metrics

CVSS v4.0
9.3
Severity
CRITICAL
Fixed in
163
Affected Products
1

Fix available

163
Patch commits
Affected packages
  • AWS / AWS Ops Wheel
    < 163 (from 0)
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:L/SI:L/SA:L
CVE-2026-6911: Authentication Bypass via Missing JWT Signature Verification in AWS Ops Wheel | HarborGuard CVE