GPU VulnDB

Database/Control plane, storage & DevOps

Ansible Automation Platform UI: DOM XSS via unvalidated `next` redirect parameter

CVSS 5.4CVE-2026-106033Control plane, storage & DevOpscurated

Impact

The Platform UI's redirect route takes the next query parameter and assigns it straight to location.href without checking scheme or format, bypassing the URL validation the platform already has for javascript: and data: URIs elsewhere. A crafted link opened by a signed-in user runs attacker JavaScript in that user's session. This matters because of what the platform is: on a fleet it is the thing that pushes configuration and runs playbooks as root across nodes, so a hijacked operator session is a path toward job templates and stored credentials rather than just defaced UI. Exploitation needs an authenticated user to click the link; the flaw gives script execution in the browser, not code execution on the controller.

Who can reach it

Remote attacker with no platform account, delivering a link to an already-authenticated Automation Platform user. Requires that user interaction (vendor vector PR:L/UI:R).

What to do

Apply the Automation Platform UI update when Red Hat ships it for your 2.x stream and restart the platform services - a controller-side package update and service restart, not a fleet-wide action, so managed nodes are untouched. Check the Red Hat CVE page and Bugzilla 2546603 for fixed package versions; the record here does not name one. Until it lands, the practical mitigation is operator awareness of links into the platform UI, since the flaw is in a route that only matters when a logged-in user follows a crafted URL.

References

Related entries

All Control plane, storage & DevOps entries

This entry is curated: imported from vendor advisories with machine assistance, not yet individually verified. Confirm against your vendor's advisory before acting, and report anything wrong.