CVE-2026-18481 - Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft

Published 2026-08-20T21:35:57Zef375097ba3a35f78bb5657e0ecd2bed7f288b0a04b92356103d323b8ee53154

Source metadata

Publication date
2026-08-20T21:35:57Z
Source identifier
295368f7ffb7cf48758e2cf6dbe1ffced77d26d6
Public record ID
record:sha256:ef375097ba3a35f78bb5657e0ecd2bed7f288b0a04b92356103d323b8ee53154

This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.

Evidence and limitations

Source ID
aws_security_bulletins
Record identifier
ef375097ba3a35f78bb5657e0ecd2bed7f288b0a04b92356103d323b8ee53154
Record type
Source metadata

This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.