Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 06 Oct 2026 20:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Metrics |
ssvc
|
Tue, 06 Oct 2026 18:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Specifically, the application extracts a target destination from the next query parameter and directly assigns it to the browser's location.href without verifying its format or scheme. The platform includes built-in URL validation functions designed to block malicious URI schemes (such as javascript: and data:) as well as off-site or protocol-relative redirects, this specific route bypasses those controls. Consequently, an attacker can craft a malicious link that, when accessed by an authenticated user, causes arbitrary JavaScript to execute within the context of the user's session. | |
| Title | Ansible: ansible-ui: ansible ui dom xss in /redirect next parameter | |
| First Time appeared |
Redhat
Redhat ansible Automation Platform Redhat hummingbird |
|
| Weaknesses | CWE-79 | |
| CPEs | cpe:/a:redhat:ansible_automation_platform:2 cpe:/a:redhat:hummingbird:1 |
|
| Vendors & Products |
Redhat
Redhat ansible Automation Platform Redhat hummingbird |
|
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: redhat
Published:
Updated: 2026-10-06T19:29:20.125Z
Reserved: 2026-10-06T13:41:51.102Z
Link: CVE-2026-106033
Updated: 2026-10-06T19:25:55.903Z
Status : Awaiting Analysis
Published: 2026-10-06T19:17:41.843
Modified: 2026-10-06T20:17:16.840
Link: CVE-2026-106033
No data.
OpenCVE Enrichment
Updated: 2026-10-06T19:45:04Z