Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft
UnratedCVE-2026-18481 · Published Jul 31, 2026 · updated Sep 22, 2026
Bulletin ID: 2026-068-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/31/2026 11:00 AM PDT Description: AWS Ops Wheel is an open-source operational decision-making tool published under the AWS GitHub organization and self-deployed by customers into their own AWS accounts via CloudFormation. The application did not sufficiently validate the participant URL field — server-side validation checked only the value's length, not whether it was a safe web URL (CWE-79) — so a user with participant-management permission (a Wheel Admin/Admin) could store a crafted URL that could execute script in another user's authenticated browser session (stored cross-site scripting). Impact is confined to a single self-deployed instance (each deployment has its own Cognito user pool); there is no cross-deployment impact and no impact to any AWS-managed service. Impacted versions: AWS Ops Wheel v2 deployments PR #168 and earlier Resolution: This issue has been addressed in PR #168 with defense-in-depth: server-side validation now restricts participant URLs to http/https schemes on create and update; the client hardens how stored URLs are rendered; and session tokens a...
Affected versions
Details and references
Bulletin ID: 2026-068-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/31/2026 11:00 AM PDT Description: AWS Ops Wheel is an open-source operational decision-making tool published under the AWS GitHub organization and self-deployed by customers into their own AWS accounts via CloudFormation. The application did not sufficiently validate the participant URL field — server-side validation checked only the value's length, not whether it was a safe web URL (CWE-79) — so a user with participant-management permission (a Wheel Admin/Admin) could store a crafted URL that could execute script in another user's authenticated browser session (stored cross-site scripting). Impact is confined to a single self-deployed instance (each deployment has its own Cognito user pool); there is no cross-deployment impact and no impact to any AWS-managed service. Impacted versions: AWS Ops Wheel v2 deployments PR #168 and earlier Resolution: This issue has been addressed in PR #168 with defense-in-depth: server-side validation now restricts participant URLs to http/https schemes on create and update; the client hardens how stored URLs are rendered; and session tokens are no longer stored in a location accessible to page scripts. Because AWS Ops Wheel is deployed from source, we recommend updating your checkout to a revision that includes this fix, redeploying both the API and UI, and ensuring any forked or derivative code is patched. Workarounds: Until you can redeploy the patched code: restrict Wheel Admin/Admin permissions to trusted users only; audit stored participants and remove any participant URL that is not a standard http/https URL; avoid interacting with participant entries originating from unintended users; and apply a strict Content-Security-Policy at your CloudFront/reverse proxy (a partial stopgap, not a substitute for the patch). References: CVE-2026-18481 GHSA-6rr8-cf9x-pj23 Please email aws-security@amazon.com with any security questions or concerns. "},"metadata":{"tags":[]}},{"fields":{"patternBoolean2":"false","id":"ams#rt-rich-textc2#pattern-data"},"metadata":{"tags":[{"name":"pattern-data","description":"Default pattern data","id":"ams#rt-rich-textc2#pattern-data","namespaceId":"rt-rich-text"}]}}]},"metadata":{"auth":{},"testAttributes":{}},"context":{"page":{"pageUrl":"https://aws.amazon.com/security/security-bulletins/2026-068-aws/"},"contentType":"page","environment":{"stage":"prod","region":"us-west-2"},"sdkVersion":"2.0.27"},"refMap":{"manifest.js":"cda3e8d042","rt-rich-text.js":"5043b0a87f","rt-rich-text.rtl.css":"6a04028f86","rt-rich-text.css":"98f5a6aee4","rt-rich-text.css.js":"3d619cc2e1","rt-rich-text.rtl.css.js":"ccdb945d3e"},"settings":{"templateMappings":{"patternHeading":"patternHeading","patternSubheading":"patternSubheading","patternDark":"patternBoolean2","title":"itemHeading","bodyText":"itemLongLoc"}}} CVE-2026-18481 - Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft Bulletin ID: 2026-068-AWS Scope: AWS Content Type: Important (requires attention) Publication Date: 07/31/2026 11:00 AM PDT Description: AWS Ops Wheel is an open-source operational decision-making tool published under the AWS GitHub organization and self-deployed by customers into their own AWS accounts via CloudFormation. The application did not sufficiently validate the participant URL field — server-side validation checked only the value's length, not whether it was a safe web URL (CWE-79) — so a user with participant-management permission (a Wheel Admin/Admin) could store a crafted URL that could execute script in another user's authenticated browser session (stored cross-site scripting). Impact is confined to a single self-deployed instance (each deployment has its own Cognito user pool); there is no cross-deployment impact and no impact to any AWS-managed service. Impacted versions: AWS Ops Wheel v2 deployments PR #168 and earlier Resolution: This issue has been
- Severity from
- no source yet
More AWS advisories
All AWS| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Aug 4 | AWS: code execution | Unrated | No fix yet |
| Aug 4 | Issue with Amazon Bedrock AgentCore harness – Insufficient Input Validation | Unrated | No fix yet |
| Aug 3 | Disabled SSH host key verification in AWS CLI EMR helper commands | Unrated | No fix yet |
| Aug 3 | Broker Credential and OAuth Token Disclosure in AWS Labs Amazon MQ MCP Server via Prompt... | Unrated | No fix yet |
| Jul 31 | Incorrect authorization in Strands Agents Tools http_request tool | Unrated | No fix yet |
| Jul 30 | Incomplete fix for CVE-2025-4318 code injection in Amazon... | Unrated | No fix yet |