CVE-2026-6912
HIGHDescription
Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165 allows remote authenticated users to escalate to deployment admin privileges and manage Cognito user accounts via a crafted UpdateUserAttributes API call that sets the custom:deployment_admin attribute. To remediate this issue, users should redeploy from the updated repository and ensure any forked or derivative code is patched to incorporate the new fixes.
Is your site exposed to CVE-2026-6912?
Run a free security scan — no signup, results in seconds.
CVSS v3.1 Score
EPSS — Exploit Prediction
EPSS estimates the probability that this vulnerability will be exploited in the wild within the next 30 days. A higher score means more likely to be exploited.
Weakness Type (CWE)
References
Frequently Asked Questions
What is CVE-2026-6912? +
How severe is CVE-2026-6912? +
How do I check if I'm vulnerable to CVE-2026-6912? +
Related Vulnerabilities
Improperly Controlled Modification of Dynamically-Determined Object Attributes vulnerability in ash-project ash_oban allows a user whose input reaches the :args option …
FOSSBilling is a free, open-source billing and client management system. Prior to version 0.8.0, an unauthenticated mass assignment vulnerability in …
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, …
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to 3.1.3, the …
Flowise is a drag & drop user interface to build a customized large language model flow. Prior to version 3.1.2, …
A Privilege Escalation through a Mass Assignment exists in Camaleon CMS When a user wishes to change his password, the …