OCTOBER 10, 2026
Live Feed
Back to database
Case File

CVE-2026-84683

HIGH · CVSS 8.7 EPSS 0.26%

Source: NVD + CISA KEV + EPSS · Published 2026-09-23 · Last synced 2026-10-10

CyberRota Analysis

AI-Generated

The vulnerability exists in the Red Hat Ansible Automation Platform's automation controller, where ANSI terminal escape sequences are not properly sanitized before being converted to HTML. This flaw allows low-privileged users to embed malicious JavaScript links in output that, when accessed by higher-privileged users, can execute arbitrary code within their authenticated sessions, potentially leading to full platform compromise. Organizations using this platform, especially those with varying privilege levels among users, should prioritize patching this vulnerability to mitigate the risk of exploitation.

CVE
CVE-2026-84683
Severity
HIGH
CVSS
8.7
EPSS
0.26%
Java

Original NVD Description

A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but does not remove ANSI terminal escape sequences before conversion to HTML. An ANSI OSC 8 hyperlink sequence in the output is expanded into an HTML anchor whose href is not scheme- filtered or escaped, so a low-privileged user who can produce output -- or an external party whose data a playbook echoes -- can embed a javascript: link that is rendered into a text/html response with no Content-Security-Policy. When a higher-privileged user views the output page and clicks the link, attacker- controlled JavaScript executes in their authenticated session, allowing actions as that user up to full platform takeover.