Wheel before PR #168 might allow an authenticated remote user to steal
session tokens and escalate to full administrative control of the
deployed instance via a crafted participant_url value containing a
dangerous URI scheme.
To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.
No advisories yet.
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
Fri, 31 Jul 2026 20:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| References |
|
Fri, 31 Jul 2026 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Fri, 31 Jul 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative control of the deployed instance via a crafted participant_url value containing a dangerous URI scheme. To remediate this issue, users should redeploy from the latest version of aws-ops-wheel. | |
| Title | Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft | |
| First Time appeared |
Aws
Aws aws Ops Wheel |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:2.3:a:aws:aws_ops_wheel:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Aws
Aws aws Ops Wheel |
|
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: AMZN
Published:
Updated: 2026-07-31T19:52:59.881Z
Reserved: 2026-07-31T12:40:04.618Z
Link: CVE-2026-18481
Updated: 2026-07-31T18:52:30.103Z
No data.
No data.
OpenCVE Enrichment
No data.