CVE-2026-44192: A flaw was found in the Ansible Lightspeed Model Context Protocol (MCP) server. This vulnerability, known as path traver
Summary
A path traversal vulnerability (a flaw that lets attackers access files outside their intended directory) was discovered in the Ansible Lightspeed Model Context Protocol (MCP) server, allowing attackers to manipulate an AI agent through indirect prompt injection (tricking an AI by hiding malicious instructions in its input). This flaw can enable attackers to write files to unauthorized locations on a user's system, potentially exposing sensitive information and allowing them to execute malicious commands that could fully compromise the system.
Vulnerability Details
6.6(medium)
EPSS: 0.0%
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:H/I:L/A:L
local
low
none
required
July 22, 2026
Classification
Taxonomy References
Affected Vendors
Related Issues
Original source: https://nvd.nist.gov/vuln/detail/CVE-2026-44192
First tracked: July 22, 2026 at 02:07 PM
Classified by LLM (prompt v3) · confidence: 85%