Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165 allows remote authenticated users to escalate to deployment admin privileges and manage Cognito user accounts via a crafted UpdateUserAttributes API call that sets the custom:deployment_admin attribute.
To remediate this issue, users should redeploy from the updated repository and ensure any forked or derivative code is patched to incorporate the new fixes.
Metrics
Affected Vendors & Products
References
History
Fri, 24 Apr 2026 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 24 Apr 2026 16:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165 allows remote authenticated users to escalate to deployment admin privileges and manage Cognito user accounts via a crafted UpdateUserAttributes API call that sets the custom:deployment_admin attribute. To remediate this issue, users should redeploy from the updated repository and ensure any forked or derivative code is patched to incorporate the new fixes. | |
| Title | Privilege Escalation via Self-Writable Cognito Custom Attribute in AWS Ops Wheel | |
| First Time appeared |
Aws
Aws aws Ops Wheel |
|
| Weaknesses | CWE-915 | |
| CPEs | cpe:2.3:a:aws:aws_ops_wheel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws Ops Wheel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-04-24T16:48:22.475Z
Reserved: 2026-04-23T13:38:11.080Z
Link: CVE-2026-6912
Updated: 2026-04-24T16:48:19.563Z
Status : Awaiting Analysis
Published: 2026-04-24T17:16:22.377
Modified: 2026-04-24T17:56:41.280
Link: CVE-2026-6912
No data.