To remediate this issue, users should redeploy from the updated repository and ensure any forked or derivative code is patched to incorporate the new fixes.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 24 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165 allows remote authenticated users to escalate to deployment admin privileges and manage Cognito user accounts via a crafted UpdateUserAttributes API call that sets the custom:deployment_admin attribute. To remediate this issue, users should redeploy from the updated repository and ensure any forked or derivative code is patched to incorporate the new fixes. | |
| Title | Privilege Escalation via Self-Writable Cognito Custom Attribute in AWS Ops Wheel | |
| First Time appeared |
Aws
Aws aws Ops Wheel |
|
| Weaknesses | CWE-915 | |
| CPEs | cpe:2.3:a:aws:aws_ops_wheel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws Ops Wheel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-04-24T16:48:22.475Z
Reserved: 2026-04-23T13:38:11.080Z
Link: CVE-2026-6912
Updated: 2026-04-24T16:48:19.563Z
Status : Awaiting Analysis
Published: 2026-04-24T17:16:22.377
Modified: 2026-04-24T17:56:41.280
Link: CVE-2026-6912
No data.
OpenCVE Enrichment
No data.