PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-44192 Red Hat CVE debrief

A path traversal vulnerability was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This flaw allows an attacker to manipulate an AI agent through indirect prompt injection, potentially leading to sensitive host information exposure and malicious command execution. The vulnerability has a CVSS score of 6.6 and is classified as medium severity. Users of Ansible Lightspeed Model Context Protocol server should be aware of this vulnerability and take steps to mitigate it. The vulnerability can result in the exposure of sensitive host information and enable the attacker to execute malicious commands, potentially leading to a full system compromise.

Vendor
Red Hat
Product
Red Hat Ansible Automation Platform 2
CVSS
MEDIUM 6.6
CISA KEV
Not listed in stored evidence
Original CVE published
2026-07-22
Original CVE updated
2026-07-22
Advisory published
2026-07-22
Advisory updated
2026-07-22

Who should care

Users of Ansible Lightspeed Model Context Protocol server, security teams, and operators should be aware of this path traversal vulnerability and take steps to mitigate it. Affected deployments should be identified, and owners assigned for follow-up. Compensating controls should be reviewed for exposed systems while remediation is scheduled and verified.

Technical summary

The Ansible Lightspeed Model Context Protocol (MCP) server is vulnerable to path traversal. An attacker can manipulate an AI agent through indirect prompt injection, causing the server to write files to unauthorized locations on the user's system. This can result in sensitive host information exposure and enable malicious command execution. The vulnerability has a CVSS score of 6.6, indicating medium severity. Users should review and update Ansible Lightspeed Model Context Protocol server configurations to prevent unauthorized access and implement monitoring to detect potential exploitation attempts.

Defensive priority

Medium priority given the CVSS score of 6.6 and potential impact.

Recommended defensive actions

  • Review and update Ansible Lightspeed Model Context Protocol server configurations to prevent unauthorized access.
  • Implement monitoring to detect potential exploitation attempts.
  • Apply vendor patches or workarounds as available.
  • Confirm whether affected product deployments exist in managed environments and assign an owner for follow-up.
  • Review the supplied official advisory or CVE record to validate affected scope, severity, and vendor guidance.
  • Plan vendor-supported updates or mitigations through normal change control where exposure is confirmed.
  • Check relevant monitoring, detection, and logs for exposed assets that need extra review.

Evidence notes

Evidence is based on CVE and NVD records. Further verification is recommended. The Ansible Lightspeed Model Context Protocol (MCP) server's path traversal vulnerability allows attackers to manipulate AI agents through indirect prompt injection, potentially exposing sensitive host information and enabling malicious command execution. Defenders should verify affected deployments, review official advisories, and plan for vendor-supported updates or mitigations.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-44192 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-44192

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-44192 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-44192

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.