Threaticon
Toggle sidebar

You're viewing a limited, public preview. Log in for full access.

Log in User Guide
Log in Get started
Vulnerabilities CVE-2026-18481

CVE-2026-18481

High
Open
TLP:CLEAR

Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft

AI Analysis

No AI analysis yet.

Description

Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative control of the deployed instance via a crafted participant_url value containing a dangerous URI scheme. To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.

Details

CVSS Score
7.3
EPSS Score
0.28%

20.7th percentile

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:N
Confidence
90%
Published
Jul 31, 2026
Last Modified
Jul 31, 2026
No notes yet. Click "Add Note" to create the first analysis note.
No opinions yet. Be the first to assess this intelligence.
Leaving Threaticon

This link opens an external site that isn't part of the platform.