A vulnerability categorized as problematic has been discovered in AWS Ops Wheel. Affected is an unknown function of the component Participant URL Handler. Executing a manipulation of the argument participant_url can lead to cross site scripting.

This vulnerability is registered as CVE-2026-18481. It is possible to launch the attack remotely. No exploit is available.

Applying a patch is advised to resolve this issue.