MEDIUM 5.4 NVD
CVE-2026-106033
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route
A DOM-based Cross-Site Scripting (XSS) vulnerability exists in the Ansible Platform UI due to unvalidated input handling within the application's redirect route. Specifically, the application extracts a target destination from the next query parameter and directly assigns it to the browser's location.href without verifying its format or scheme. The platform includes built-in URL validation functions designed to block malicious URI schemes (such as javascript: and data:) as well as off-site or protocol-relative redirects, this specific route bypasses those controls. Consequently, an attacker can craft a malicious link that, when accessed by an authenticated user, causes arbitrary JavaScript to execute within the context of the user's session.
References
- https://access.redhat.com/security/cve/CVE-2026-106033
- https://bugzilla.redhat.com/show_bug.cgi?id=2546603
This medium severity vulnerability with a CVSS score of 5.4 was published on 2026-10-06 via NVD.
vulnfeed aggregates 9512 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.