Junglewise Threat Intelligence

CVE-2026-6912: AWS Ops Wheel auth bypass and privilege escalation in v2 API

CVE-2026-6912 · Severity: high · Published 2026-04-24

Technologies: Amazon AWS. Vendors: AWS, Amazon Web Services, Amazon.

Executive brief

AWS Ops Wheel, an open-source tool for making random team selections, contains security flaws that could allow unauthorized individuals to take control of the application. Attackers could bypass security checks to read, modify, or delete application data and manage user accounts. This could lead to a total compromise of the tool's data and unauthorized access to the associated user directory.

Technical details

AWS Ops Wheel v2 is affected by two distinct vulnerabilities. CVE-2026-6911 is an authentication bypass caused by the failure to enforce JWT token signature verification in the v2 API; an unauthenticated remote attacker can craft a malicious token to gain full administrative access to the API Gateway endpoint. CVE-2026-6912 is a privilege escalation vulnerability where insufficient restrictions on Cognito User Pool attribute write permissions allow an authenticated user to modify their own attributes to gain elevated privileges. These issues have been addressed in PR #164 and PR #165, respectively.

Affected products

  • AWS Ops Wheel v2 deployments PR-163 and earlier

CVE identifiers

  • CVE-2026-6912
  • CVE-2026-6911

Timeline

  • 2026-04-24: disclosed
  • 2026-04-24: patched
  • 2026-04-24: advisory

References

Related threats