Security researchers warned that common Amazon Cognito User Pools configurations can let authenticated users directly modify their own profile data in ways that undermine application security. The report highlights that Cognito access tokens often include the default scope aws.cognito.signin.user.admin, and when developers also allow broad attribute read/write permissions, users can call the UpdateUserAttributes API to change values such as custom privilege flags or other application-relevant fields stored in Cognito.
The findings also describe broader design pitfalls that can expose Cognito directly to attackers, including selecting SPA or mobile app client types that reveal enough information for direct authentication attempts, leaving self-sign-up enabled unintentionally, permitting alternate auth flows that bypass server-side controls, and relying on Cognito attributes for authorization decisions. Researchers said organizations should minimize readable and writable attributes, avoid storing sensitive authorization state in user attributes, disable unnecessary authentication flows, prefer traditional web application clients when direct client-side Cognito access is not required, and review logout, token revocation, and lockout behavior carefully.

See affected versions and whether adversaries are exploiting it.
1 event from the most recent confirmed update back to the earliest known activity.
A technical blog post analyzes ten security pitfalls and misconfigurations in AWS Cognito User Pools, including writable attributes, exposed tokens, self-sign-up, weak auth-flow combinations, and logout limitations. It recommends minimizing attribute permissions, avoiding sensitive authorization state in Cognito attributes, disabling unnecessary auth flows, and preferring traditional web application clients when direct client-side Cognito access is not intended.
Vulnerabilities, threat actors, malware, products, organizations, and breaches Mallory has linked to this story.
See whether adversaries are exploiting this yet, and where the affected versions run in your environment.
2 references tracked. Mallory keeps watching after this page renders.
Map indicators from this story to your assets and identify affected systems in minutes.
Every observed campaign, victim, and pivot linked to actors named in this story.
Malware, exploits, and IOCs connected to the activity described here.
YARA, Sigma, and Snort rules deployed to your SIEM as soon as they’re published.
Get matching new stories delivered to your team as they break — not the next morning.
Ask questions about this story and take action on the answers.