CVE-2026-18481 - Stored XSS in Participant URL Field leads to Account Takeover via Session Token Theft
Published 2026-08-20T21:35:57Z•ef375097ba3a35f78bb5657e0ecd2bed7f288b0a04b92356103d323b8ee53154
Source metadata
- Publication date
- 2026-08-20T21:35:57Z
- Source identifier
- 295368f7ffb7cf48758e2cf6dbe1ffced77d26d6
- Public record ID
- record:sha256:ef375097ba3a35f78bb5657e0ecd2bed7f288b0a04b92356103d323b8ee53154
This is source-provided metadata, not an enriched summary or an impact assessment. Follow the canonical source link for the published material.
Evidence and limitations
- Source ID
- aws_security_bulletins
- Record identifier
- ef375097ba3a35f78bb5657e0ecd2bed7f288b0a04b92356103d323b8ee53154
- Record type
- Source metadata
This record may overlap with other records. Source metadata can be incomplete or change. Validate consequential decisions against the linked source and your own environment.