Back

MEDIUM

Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft

Published Jul 31, 2026

Description

Stored cross-site scripting in the participant URL handling in AWS Ops Wheel before PR #168 might allow an authenticated remote user to steal session tokens and escalate to full administrative control of the deployed instance via a crafted participant_url value containing a dangerous URI scheme.

To remediate this issue, users should redeploy from the latest version of aws-ops-wheel.

Affected products

Remediation

No remediation recorded yet.

References (4)

Change history (0)

No recorded changes yet.

Sources

CVE.org / MITRE

Status PUBLISHED
Assigner AMZN
Published Jul 31, 2026
Updated Jul 31, 2026
Reserved Jul 31, 2026

CISA Vulnrichment

Updated Jul 31, 2026

NVD

Status Awaiting Analysis
Modified Aug 4, 2026

Red Hat

No data

ENISA EUVD

Assigner AMZN
Published Jul 31, 2026
Updated Jul 31, 2026

GitHub

No data