Stored Cross-Site Scripting Vulnerability in AWS Ops Wheel
CVE-2026-18481

6.2MEDIUM

Key Information:

Vendor

Aws

Vendor
CVE Published:
31 July 2026

What is CVE-2026-18481?

A stored cross-site scripting vulnerability exists in the participant URL handling of AWS Ops Wheel prior to PR #168. This flaw enables an authenticated remote user to manipulate the participant_url value, potentially allowing them to embed a harmful URI scheme. If exploited, it can result in the theft of session tokens and facilitate unauthorized escalation to full administrative control of the deployed instance. Users are advised to address this security issue by redeploying from the latest version of AWS Ops Wheel.

Affected Version(s)

AWS Ops Wheel 0

References

CVSS V4

Score:
6.2
Severity:
MEDIUM
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
Unknown

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.