CVE-2026-44188
Last modified
CVE-2026-44188 is a medium-severity vulnerability rated 5.3/10 on the CVSS scale. A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible Lightspeed instance. EPSS estimates a 0.28% chance of exploitation in the next 30 days.
Description
A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible Lightspeed instance. If an attacker exfiltrates a valid OAuth (Open Authorization) access token before a user logs out, they can continue to authenticate and access sensitive data. This is because the application fails to invalidate the token on the backend, leaving it valid until its natural expiration. This can lead to unauthorized read access to Ansible resources such as inventories, playbooks, and configuration data.
Metrics
CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Red Hat | Red Hat Ansible Automation Platform 2.7 | All versions |
| Red Hat | Red Hat Ansible Automation Platform 2 | All versions |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-44188?
How severe is CVE-2026-44188?
How do I fix CVE-2026-44188?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-44182Jupyter Enterprise Gateway launches remote Jupyter Notebook …10
- CVE-2026-44183Cleanuparr is a tool for automating the cleanup of unwanted …9.8
- CVE-2026-44184Cleanuparr is a tool for automating the cleanup of unwanted …8
- CVE-2026-44185Buffer Over-read vulnerability in Apache HTTP Server via out…7.3
- CVE-2026-44186Loop with Unreachable Exit Condition ('Infinite Loop') vulne…7.3
- CVE-2026-44187A flaw was found in the Ansible Lightspeed extension for Vis…3.3
- CVE-2026-44189A flaw was found in the Visual Studio Code Ansible Lightspee…7.8
- CVE-2026-44190A flaw was found in the Ansible Lightspeed Visual Studio Cod…7.8
- CVE-2026-44191A flaw was found in the Visual Studio Code Ansible Lightspee…7.8
- CVE-2026-44192A flaw was found in the Ansible Lightspeed Model Context Pro…6.6
- CVE-2026-44193OPNsense is a FreeBSD based firewall and routing platform. P…9.1
- CVE-2026-44194OPNsense is a FreeBSD based firewall and routing platform. P…9.1
Are you affected by CVE-2026-44188?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
