SEPTEMBER 20, 2026
Live Feed
Back to database
Case File

CVE-2026-44192

MEDIUM · CVSS 6.6 EPSS 0.15%

Source: NVD + CISA KEV + EPSS · Published 2026-07-22 · Last synced 2026-08-21

CyberRota Analysis

AI-Generated

A path traversal vulnerability in the Ansible Lightspeed Model Context Protocol (MCP) server allows attackers to manipulate AI agents via indirect prompt injection, resulting in unauthorized file writing on the user's system. This could lead to the exposure of sensitive information and enable the execution of malicious commands, posing a risk of full system compromise. Organizations utilizing Ansible Lightspeed should prioritize addressing this vulnerability to mitigate potential security breaches.

CVE
CVE-2026-44192
Severity
MEDIUM
CVSS
6.6
EPSS
0.15%

Original NVD Description

A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traversal, allows an attacker to manipulate an AI agent through indirect prompt injection. By doing so, the attacker can cause the server to write files to unauthorized locations on the user's system. This can result in the exposure of sensitive host information and enable the attacker to execute malicious commands, potentially leading to a full system compromise.