
CVE-2026-13140 Stored Cross-Site Scripting in the exposed AWS API key store of Thinkst Applied Research Canarytokens. Anonymous exploitation requires knowledge of a random identifier. This issue affects Ca... https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-13140
Post summary
The CVE-2026-13140 reports a stored XSS in Thinkst Canarytokens’ exposed AWS API key store, requiring a random identifier for exploitation, with no evidence of a PoC, exploit code, active use, or patching guidance.
