Database/Control plane, storage & DevOps
Ansible Automation Platform UI: DOM XSS via unvalidated `next` redirect parameter
Impact
The Platform UI's redirect route takes the next query parameter and assigns it straight to location.href without checking scheme or format, bypassing the URL validation the platform already has for javascript: and data: URIs elsewhere. A crafted link opened by a signed-in user runs attacker JavaScript in that user's session. This matters because of what the platform is: on a fleet it is the thing that pushes configuration and runs playbooks as root across nodes, so a hijacked operator session is a path toward job templates and stored credentials rather than just defaced UI. Exploitation needs an authenticated user to click the link; the flaw gives script execution in the browser, not code execution on the controller.
Who can reach it
Remote attacker with no platform account, delivering a link to an already-authenticated Automation Platform user. Requires that user interaction (vendor vector PR:L/UI:R).
What to do
Apply the Automation Platform UI update when Red Hat ships it for your 2.x stream and restart the platform services - a controller-side package update and service restart, not a fleet-wide action, so managed nodes are untouched. Check the Red Hat CVE page and Bugzilla 2546603 for fixed package versions; the record here does not name one. Until it lands, the practical mitigation is operator awareness of links into the platform UI, since the flaw is in a route that only matters when a logged-in user follows a crafted URL.
References
Related entries
- GitLab CE/EE: missing enforcement checks let an authenticated user bypass SAML SSO restrictionsCVE-2026-12910 · GitLab CE/EE (SAML SSO sign-in enforcement)Medium
- Grafana: an Editor can mark a dashboard file-provisioned, making it undeletable by adminsCVE-2026-13720 · Grafana dashboard API (grafana.app/managedBy provisioning annotations)Medium
- GitLab EE: missing namespace validation lets a user apply compliance frameworks from namespaces they cannot accessCVE-2026-4398 · GitLab EE self-managed (compliance framework namespace validation)Medium
- LibreNMS: reflected XSS in the Proxmox view runs script in a logged-in monitoring user's sessionCVE-2026-45694 · LibreNMS (Proxmox application view, instance and vmid parameters)Medium
- Strimzi: partial Entity Operator deployments still get both operators' RBAC, over-granting the SACVE-2026-55226 · Strimzi Kafka Operator (Entity Operator ServiceAccount RBAC)Medium
- Jenkins Stapler: form binding writes public static fields, applying changes instance-wideCVE-2026-84654 · Jenkins Stapler (form data binding to public static fields)Medium
This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.