AWS Ops Wheel JWT Signature Bypass (CVE-2026-6911)
CVE-2026-6911 Published on April 24, 2026
Authentication Bypass via Missing JWT Signature Verification in AWS Ops Wheel
Missing JWT signature verification in AWS Ops Wheel allows unauthenticated attackers to forge JWT tokens and gain unintended administrative access to the application, including the ability to read, modify, and delete all application data across tenants and manage Cognito user accounts within the deployment's User Pool, via a crafted JWT sent to the API Gateway endpoint.
To remediate this issue, users should redeploy from the updated repository and ensure any forked or derivative code is patched to incorporate the new fixes.
Vulnerability Analysis
CVE-2026-6911 can be exploited with network access, and does not require authorization privileges or user interaction. This vulnerability is considered to have a low attack complexity. The potential impact of an exploit of this vulnerability is considered to be critical as this vulnerability has a high impact to the confidentiality, integrity and availability of this component.
Weakness Type
Improper Verification of Cryptographic Signature
The software does not verify, or incorrectly verifies, the cryptographic signature for data.
Products Associated with CVE-2026-6911
stack.watch emails you whenever new vulnerabilities are published in Aws Ops Wheel or Amazon Aws. Just hit a watch button to start following.
Affected Versions
AWS Ops Wheel:- Before 163 is affected.