Answer in brief
CVE-2026-44188 records a Medium severity (CVSS 5.3) vulnerability in Ansible-lightspeed: ansible lightspeed: session hijacking and unauthorized data access due to insufficient session expiration. The current sources do not mark it as known exploited. The current feed maps Red Hat/ansible-automation-platform-24/lightspeed-rhel8 (generic), Red Hat/ansible-automation-platform-25/lightspeed-rhel8 (generic). Check affected ranges and fixed versions before updating.
Analysis pending evidence review
HOL Guard separates source facts from reviewed analysis. See the methodology.
CVSS is 5.3. The current sources do not mark it as known exploited. Treat this as a source-backed prioritization signal, not a statement about your environment.
Analysis status
Analysis pending evidence review
Factual feed record only; HOL analysis is not approved for indexing. Read the methodology.
The current feed maps Red Hat/ansible-automation-platform-24/lightspeed-rhel8 (generic), Red Hat/ansible-automation-platform-25/lightspeed-rhel8 (generic). Check affected ranges and fixed versions before updating.
| Package | Affected range | Fixed version |
|---|---|---|
| Red Hat/ansible-automation-platform-24/lightspeed-rhel8generic | * | Not reported |
| Red Hat/ansible-automation-platform-25/lightspeed-rhel8generic | * | Not reported |
Published upstream
Jun 15, 2026
Evidence: source:cvelist:source_dates:source-dates:recordSource modified
Aug 20, 2026
Evidence: source:cvelist:source_dates:source-dates:recordFirst seen by HOL
Aug 20, 2026
A flaw was found in Ansible Lightspeed. This vulnerability, related to insufficient session expiration, allows a remote attacker to maintain persistent access to the Ansible Lightspeed instance. If an attacker exfiltrates a valid OAuth (Open Authorization) access token before a user logs out, they can continue to authenticate and access sensitive data. This is because the application fails to invalidate the token on the backend, leaving it valid until its natural expiration. This can lead to unauthorized read access to Ansible resources such as inventories, playbooks, and configuration data.
Quoted source text, attributed separately from HOL analysis.