CVE-2026-44188 Details
Description
A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible Lightspeed instance. If an attacker exfiltrates a valid OAuth (Open Authorization) access token before a user logs out, they can continue to authenticate and access sensitive data. This is because the application fails to invalidate the token on the backend, leaving it valid until its natural expiration. This can lead to unauthorized read access to Ansible resources such as inventories, playbooks, and configuration data.
A vulnerability in Red Hat Ansible Lightspeed has been identified, stemming from inadequate session expiration. This flaw enables a remote attacker to retain persistent access to an Ansible Lightspeed instance. If an attacker obtains a valid OAuth access token before a user logs out, they can continue to authenticate and access sensitive information. The application does not invalidate the token on the backend, allowing it to remain active until its natural expiration. Consequently, this vulnerability could result in unauthorized read access to Ansible resources, including inventories, playbooks, and configuration data.
Users can upgrade to Red Hat Ansible Automation Platform 2.7 to address this vulnerability. For instructions on how to apply this update, refer to the Red Hat Ansible Automation Platform 2.7 Upgrade Guide.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 15, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-613 | Insufficient Session Expiration | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
6 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 20, 2026 | CVE Modified | [email protected] |
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jul 23, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jun 15, 2026 | New CVE Received | [email protected] |