
Cloud Vulnerability DB
A community-led vulnerabilities database
CVE-2026-44188 is an insufficient session expiration vulnerability in Ansible Lightspeed (part of Red Hat Ansible Automation Platform) that allows a remote attacker to maintain persistent unauthorized access by reusing exfiltrated OAuth access tokens. The flaw was reported on May 5, 2026, and publicly disclosed on June 15, 2026, when Red Hat issued security advisory RHSA-2026:25928. Affected products include ansible-automation-platform-27/lightspeed-rhel9, ansible-automation-platform-24/lightspeed-rhel8, and ansible-automation-platform-25/lightspeed-rhel8. It carries a CVSS v3.1 base score of 5.3 (Medium) (Red Hat Advisory, Red Hat CVE, Github Advisory).
The root cause is classified as CWE-613 (Insufficient Session Expiration): when a user logs out of Ansible Lightspeed, the application fails to invalidate the associated OAuth access token on the backend, leaving it valid until its natural expiration time. An attacker who has already obtained a valid OAuth token — for example, through network interception, credential theft, or access to token storage — can continue to use it to authenticate against the Ansible Lightspeed API even after the legitimate user has logged out. Exploitation requires the attacker to have low-level privileges and the ability to exfiltrate the token prior to logout, making the attack complexity high (Red Hat Bugzilla, Github Advisory).
Successful exploitation allows an attacker to maintain persistent read access to sensitive Ansible resources, including inventories, playbooks, and configuration data, for the remaining lifetime of the stolen OAuth token. There is no integrity or availability impact; the vulnerability is limited to confidentiality. Exposure of automation configuration data such as inventories and playbooks could facilitate lateral movement within an organization's infrastructure by revealing host details, credentials, or automation logic (Red Hat Bugzilla, Red Hat CVE).
Authorization: Bearer <token> HTTP headers).Red Hat has addressed this vulnerability in Red Hat Ansible Automation Platform 2.7 via security advisory RHSA-2026:25928, released June 15, 2026; the fixed RPM build for ansible-automation-platform-27/lightspeed-rhel9 is version 1781025813 or later. Organizations should apply this update as soon as possible by following the upgrade instructions in the Red Hat Ansible Automation Platform 2.7 documentation. As a temporary workaround, administrators can enforce shorter OAuth token lifetimes in their identity provider configuration to reduce the window of exposure for any exfiltrated tokens (Red Hat Advisory, Red Hat CVE).
Red Hat classified this advisory as "Important" severity and published the fix alongside two other CVEs (CVE-2026-44431, CVE-2026-44432, CVE-2026-48526) in the same Ansible Automation Platform 2.7 container release update. The vulnerability was noted on infosec.exchange and picked up by standard vulnerability aggregators shortly after disclosure, but no significant independent researcher commentary or broad media coverage has been identified (Red Hat Advisory).
Source: This report was generated using AI
Free Vulnerability Assessment
Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.
Get a personalized demo
"Best User Experience I have ever seen, provides full visibility to cloud workloads."
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
"We know that if Wiz identifies something as critical, it actually is."