CVE Database
/

CVE-2026-0598

Back to search

CVE-2026-0598

Published: Feb 6, 2026

Modified: May 4, 2026

PUBLISHED

CVSS v3.1

4.2

MEDIUM

Description

A security flaw was identified in the Ansible Lightspeed API conversation endpoints that handle AI chat interactions. The APIs do not properly verify whether a conversation identifier belongs to the authenticated user making the request. As a result, an attacker with valid credentials could access or influence conversations owned by other users. This exposes sensitive conversation data and allows unauthorized manipulation of AI-generated outputs.

VendorProductVersions

Red Hat

Red Hat Ansible Automation Platform 2.6

unaffected
1777387242 - < *

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Red Hat

Red Hat Ansible Automation Platform 2

All versions

Weaknesses (CWE)

CVSS v3.1 Details

CVSS v3.1 Vector

CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:L/I:L/A:N

Attack Vector

Network

Attack Complexity

High

Privileges Required

Low

User Interaction

None

Scope

Unchanged

Confidentiality

Low

Integrity

Low

Availability

None

References

RHSA-2026:13545
vendor-advisory
x_refsource_REDHAT
RHBZ#2427094
issue-tracking
x_refsource_REDHAT

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now