CVE-2026-18481 Details
Description
Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative control of the deployed instance via a crafted participant_url value containing a dangerous URI scheme. To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.
A stored cross-site scripting vulnerability has been identified in AWS Ops Wheel versions prior to PR #168. This issue arises from inadequate validation of the participant URL field, allowing an authenticated user with participant-management permissions to inject a crafted URL. The vulnerability could lead to the theft of session tokens and escalation to full administrative control of the deployed instance.
Users should update their deployment of AWS Ops Wheel to a version that includes the fix from PR #168, which enhances URL validation and improves how stored URLs are rendered. Until the update can be applied, it is recommended to restrict Wheel Admin permissions to trusted users, audit and remove any unsafe participant URLs, and apply a strict Content-Security-Policy at the CloudFront or reverse proxy level.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 31, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-79 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | AMZN |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 31, 2026 | CVE Modified | AMZN |
| Jul 31, 2026 | New CVE Received | AMZN |
| Jul 31, 2026 | CVE Modified | CISA-ADP |