
CVE-2026-6912 Improperly controlled modification of dynamically-determined object attributes in the Cognito User Pool configuration in AWS Ops Wheel before PR #165 allows remote auth… https://www.cve.org/CVERecord?id=CVE-2026-6912
Post summary
CVE-2026-6912 reveals that AWS Ops Wheel’s Cognito User Pool configuration permits remote authorization via uncontrolled modification of object attributes, and the issue is fixed in PR #165.
