Threat · curated 10 Aug 2026

NVD - CVE-2026-44192

Coverage timeline

10 Aug 2026nist.gov

Single-source advisory — first reported, latest, and curated coincide.

Why it matters

CVE-2026-44192 shows how indirect prompt injection against an MCP server can be chained into path traversal and arbitrary file writes, giving attackers a route to full host compromise through AI-agent tooling.

CVE-2026-44192 is a path-traversal flaw in the Ansible Lightspeed Model Context Protocol (MCP) server that lets an attacker manipulate an AI agent via indirect prompt injection to write files to unauthorized locations. Red Hat rates it CVSS 3.1 base 6.6 (Medium), and successful exploitation can expose sensitive host information and enable malicious command execution leading to full system compromise.