Description
Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165 allows remote authenticated users to escalate to deployment admin privileges and manage Cognito user accounts via a crafted UpdateUserAttributes API call that sets the custom:deployment_admin attribute. To remediate this issue, users should redeploy from the updated repository and ensure any forked or derivative code is patched to incorporate the new fixes.
INFO
Published Date :
2026-04-24T16:11:45.833Z
Last Modified :
2026-04-24T16:48:22.475Z
Source :
AMZN
AFFECTED PRODUCTS
The following products are affected by CVE-2026-6912 vulnerability.
| Vendors | Products |
|---|---|
| Aws |
|
REFERENCES
Here, you will find a curated list of external links that provide in-depth information to CVE-2026-6912.