PT-2026-62028 · Unknown+1 · Open-Iscsi+1
CVE-2026-44943
·
Published
2026-07-20
·
Updated
2026-08-20
CVSS v4.0
8.7
High
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X |
Name of the Vulnerable Software and Affected Versions
open-iscsi versions prior to 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e
Description
A Path Traversal issue exists where an improper limitation of a pathname to a restricted directory allows remote man-in-the-middle (MITM) attackers to create root-owned files outside the database and inject lines into the record.
Recommendations
Update to the version containing the fix for commit 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
Exploit
Fix
Path traversal
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rocky Linux
Open-Iscsi