CVE-2026-84683 Overview
CVE-2026-84683 is a stored cross-site scripting (XSS) vulnerability in Red Hat Ansible Automation Platform's automation-controller. The HTML view of job, ad hoc command, project update, and inventory update standard output escapes HTML metacharacters but fails to strip ANSI terminal escape sequences before HTML conversion. An ANSI OSC 8 hyperlink sequence expands into an HTML anchor whose href attribute is neither scheme-filtered nor escaped. A low-privileged user who can produce playbook output can embed a javascript: URI that renders in a text/html response without a Content-Security-Policy header.
Critical Impact
When a higher-privileged operator views the affected output page and clicks the injected link, attacker-controlled JavaScript executes in their authenticated session, enabling actions up to full platform takeover.
Affected Products
- Red Hat Ansible Automation Platform (automation-controller component)
- Product versions covered by advisories RHSA-2026:71113, RHSA-2026:71114, RHSA-2026:71177, and RHSA-2026:71179
- Deployments exposing job, ad hoc command, project update, or inventory update stdout HTML views
Discovery Timeline
- 2026-09-23 - CVE-2026-84683 published to NVD
- 2026-09-24 - Last updated in NVD database
Technical Details for CVE-2026-84683
Vulnerability Analysis
The flaw is classified as [CWE-79] Improper Neutralization of Input During Web Page Generation. The automation-controller renders standard output from Ansible tasks into an HTML view. The renderer escapes HTML metacharacters such as <, >, and & but does not remove ANSI terminal escape sequences prior to conversion. As a result, terminal formatting data is treated as source input for HTML transformation logic.
The specific abuse primitive is the ANSI Operating System Command (OSC) 8 sequence, which encodes hyperlinks in terminal emulators. The controller translates this sequence into an HTML <a> element and copies the URL directly into the href attribute without scheme filtering or attribute escaping. The response is served as text/html with no Content-Security-Policy header, so a javascript: URI executes on click.
Root Cause
The conversion pipeline treats ANSI OSC 8 hyperlink data as trusted structural input. The href value is passed to the DOM without validating that the scheme is http, https, or another safe protocol. The absence of a Content-Security-Policy header removes the last barrier that could block inline script execution from a javascript: URI.
Attack Vector
A low-privileged user with permission to run jobs, ad hoc commands, project updates, or inventory updates can inject the payload through any Ansible task that echoes attacker-controlled data. External data sources referenced by a playbook — such as inventory variables, API responses, or SCM content — can also carry the OSC 8 sequence. When a higher-privileged user, such as a Platform Administrator, opens the standard output view and clicks the crafted link, the injected JavaScript runs inside their authenticated session. The attacker can then invoke controller APIs, exfiltrate credentials, modify job templates, or escalate to full platform takeover.
The payload structure is a plain ANSI OSC 8 hyperlink of the form ESC ] 8 ; ; javascript:<code> ST link-text ESC ] 8 ; ; ST, echoed by any task producing standard output. No exploit code is published for this advisory; see the Red Hat CVE Analysis CVE-2026-84683 for further technical detail.
Detection Methods for CVE-2026-84683
Indicators of Compromise
- Standard output records for jobs, ad hoc commands, project updates, or inventory updates containing ANSI OSC 8 escape sequences (byte pattern 0x1B 0x5D 0x38 0x3B).
- Rendered job output HTML containing <a> elements whose href begins with javascript:, data:, or other non-web schemes.
- Unexpected authenticated API calls originating from administrator browser sessions shortly after viewing job output pages.
Detection Strategies
- Scan the controller database or job event stream for ANSI OSC 8 sequences in stdout fields before applying the vendor patch.
- Inspect web server access logs for /api/v2/jobs/*/stdout/ and equivalent endpoints followed by anomalous privileged API activity from the same session.
- Deploy a browser-side or reverse-proxy Content-Security-Policy in report-only mode to surface inline script or javascript: navigation attempts.
Monitoring Recommendations
- Alert on new or modified job templates, users, credentials, or roles created immediately after an administrator viewed a job stdout page.
- Correlate session identifiers between stdout page views and subsequent write operations against the controller API.
- Retain job output artifacts long enough to support retroactive scanning once detection signatures for OSC 8 abuse are available.
How to Mitigate CVE-2026-84683
Immediate Actions Required
- Apply the Red Hat updates referenced in advisories RHSA-2026:71113, RHSA-2026:71114, RHSA-2026:71177, and RHSA-2026:71179 to all automation-controller instances.
- Restrict job execution and inventory edit permissions to trusted users until patching is complete.
- Instruct administrators to review job output through the raw or plain text endpoint rather than the HTML view until the fix is deployed.
Patch Information
Red Hat has released fixed automation-controller packages through the following errata: RHSA-2026:71113, RHSA-2026:71114, RHSA-2026:71177, and RHSA-2026:71179. Additional context is available in the Red Hat CVE Analysis CVE-2026-84683 and Red Hat Bug Report #2527128.
Workarounds
- Front the controller with a reverse proxy that injects a strict Content-Security-Policy header disallowing inline scripts and non-web href schemes.
- Sanitize or strip ANSI escape sequences at the ingestion boundary for any playbook that consumes untrusted external data.
- Reduce the population of high-privileged accounts and require them to open job output only from segregated, hardened workstations until the patch is applied.
# Example reverse-proxy CSP header to reduce exploitability pending patch
# (NGINX snippet — adjust to your deployment)
add_header Content-Security-Policy "default-src 'self'; script-src 'self'; object-src 'none'; base-uri 'none'; frame-ancestors 'none'" always;
Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.
