CVE-2026-44192
Awaiting Analysis Awaiting Analysis - Queue

Path Traversal in Ansible Lightspeed MCP Server

Vulnerability report for CVE-2026-44192, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: Red Hat, Inc.

Description

A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injection. By doing so, the attacker can cause the server to write files to unauthorized locations on the user's system. This can result in the exposure of sensitive host information and enable the attacker to execute malicious commands, potentially leading to a full system compromise.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-08-11
AI Q&A
2026-07-22
EPSS Evaluated
2026-08-10
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
redhat ansible_lightspeed_model_context_protocol *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-44192 is a path traversal vulnerability in the Ansible Lightspeed MCP server. It allows attackers to manipulate an AI agent via indirect prompt injection, forcing the server to write files to unauthorized locations on the user's system. This can expose sensitive host information and enable malicious command execution, potentially leading to full system compromise.

Detection Guidance

Detecting this vulnerability requires monitoring for unauthorized file writes or suspicious activity in the Ansible Lightspeed MCP server. Check logs for unexpected file operations in system directories and review any AI agent interactions for indirect prompt injection attempts.

Impact Analysis

This vulnerability can allow attackers to access sensitive system files, execute malicious commands, and gain control over your system. It may lead to data breaches, unauthorized modifications, or complete system takeover if exploited.

Compliance Impact

This vulnerability could lead to unauthorized file writes and command execution, potentially exposing sensitive data. This may violate compliance requirements under GDPR (data protection) and HIPAA (health information security) by enabling unauthorized access or disclosure of protected information.

Mitigation Strategies

Immediately update the Ansible Lightspeed MCP server to the latest patched version. Restrict network access to the MCP server, disable unnecessary features, and monitor for unauthorized file writes or command executions. Consider isolating the server if possible.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-44192. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart