What is CVE-2026-18481?
CVE-2026-18481 is a Stored XSS vulnerability in the participant URL handling of AWS Ops Wheel before PR #168. An authenticated remote user can craft a participant_url value with a dangerous URI scheme to steal session tokens and escalate to full administrative control of the instance. Applying the patch is recommended.
Azərbaycanca: CVE-2026-18481, AWS Ops Wheel-də iştirakçı URL idarəetməsində saxlanılan Stored XSS zəifliyidir. PR #168-dən əvvəlki versiyalarda təsdiqlənmiş uzaq istifadəçi, təhlükəli URI sxemi olan participant_url dəyəri ilə sessiya tokenlərini oğurlaya və quraşdırılmış instansiyada tam inzibati nəzarəti ələ keçirə bilər. Patcheni tətbiq etmək tövsiyə olunur.
Related CVEs
link basis: same weakness class CWE-79
FAQ2
Does exploiting CVE-2026-18481 require the attacker to be authenticated?
Yes, exploiting CVE-2026-18481 requires the attacker to be an authenticated remote user.
What type of vulnerability is CVE-2026-18481 and what can be its impact?
It is a Stored XSS vulnerability. As a result, an attacker can steal session tokens and escalate to full administrative control of the instance.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.