PT-2026-97527 · Red Hat · Ansible Automation Platform Automation-Controller

CVE-2026-84683

·

Published

2026-09-23

·

Updated

2026-09-25

CVSS v3.1

8.7

High

VectorAV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Red Hat Ansible Automation Platform automation-controller (affected versions not specified)
Description An issue exists in the HTML view of job, ad hoc command, project update, and inventory update standard output. While HTML metacharacters are escaped, ANSI terminal escape sequences are not removed before conversion to HTML. Specifically, an ANSI OSC 8 hyperlink sequence is expanded into an HTML anchor with an href that is not scheme-filtered or escaped. This allows a low-privileged user or an external party to embed a javascript: link. Because the response lacks a Content-Security-Policy (a security layer that helps detect and mitigate certain types of attacks, including Cross-Site Scripting), the JavaScript executes in the session of a higher-privileged user who clicks the link, potentially leading to full platform takeover.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

XSS

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-84683
RHSA-2026:71113
RHSA-2026:71114

Affected Products

Ansible Automation Platform Automation-Controller