PT-2026-97527 · Red Hat · Ansible Automation Platform Automation-Controller
CVE-2026-84683
·
Published
2026-09-23
·
Updated
2026-09-25
CVSS v3.1
8.7
High
| Vector | AV:N/AC:L/PR:L/UI:R/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Red Hat Ansible Automation Platform automation-controller (affected versions not specified)
Description
An issue exists in the HTML view of job, ad hoc command, project update, and inventory update standard output. While HTML metacharacters are escaped, ANSI terminal escape sequences are not removed before conversion to HTML. Specifically, an ANSI OSC 8 hyperlink sequence is expanded into an HTML anchor with an
href that is not scheme-filtered or escaped. This allows a low-privileged user or an external party to embed a javascript: link. Because the response lacks a Content-Security-Policy (a security layer that helps detect and mitigate certain types of attacks, including Cross-Site Scripting), the JavaScript executes in the session of a higher-privileged user who clicks the link, potentially leading to full platform takeover.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
XSS
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Ansible Automation Platform Automation-Controller