Stored Cross-Site Scripting Vulnerability in AWS Ops Wheel
CVE-2026-18481
6.2MEDIUM
What is CVE-2026-18481?
A stored cross-site scripting vulnerability exists in the participant URL handling of AWS Ops Wheel prior to PR #168. This flaw enables an authenticated remote user to manipulate the participant_url value, potentially allowing them to embed a harmful URI scheme. If exploited, it can result in the theft of session tokens and facilitate unauthorized escalation to full administrative control of the deployed instance. Users are advised to address this security issue by redeploying from the latest version of AWS Ops Wheel.
Affected Version(s)
AWS Ops Wheel 0
