CVE-ID: CVE-2026-0598 Vulnerability Type: Broken Object Level Authorization (BOLA) Affected Product: Ansible Lightspeed API Affected Endpoints: - - - Streaming chat APIs Vulnerability Description: - Missing ownership validation of the parameter. - Backend does not verify if the authenticated user owns the referenced conversation. - Conversations are incorrectly mapped to a default null user ID. Impact: - Authenticated attackers can access prior conversation history. - Inject new prompts into another user's AI session. - Potentially influence generated Ansible playbooks. - Unauthorized information disclosure and integrity compromise. Status: NEW Reported: 2026-01-05 07:48 UTC Modified: 2026-02-06 05:45 UTC Priority: medium Severity: medium