PT-2026-62028 · Unknown+1 · Open-Iscsi+1

CVE-2026-44943

·

Published

2026-07-20

·

Updated

2026-08-20

CVSS v4.0

8.7

High

VectorAV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions open-iscsi versions prior to 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e
Description A Path Traversal issue exists where an improper limitation of a pathname to a restricted directory allows remote man-in-the-middle (MITM) attackers to create root-owned files outside the database and inject lines into the record.
Recommendations Update to the version containing the fix for commit 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.

Exploit

Fix

Path traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

ALSA-2026:53844
ALSA-2026:53845
AZL-94428
CVE-2026-44943
OESA-2026-3337
OESA-2026-3338
OESA-2026-3339
OESA-2026-3340
OESA-2026-3407
OPENSUSE-SU-2026:11317-1
OPENSUSE-SU-2026:21580-1
RHSA-2026:53844
RHSA-2026:53845
RHSA-2026:60427
RHSA-2026:60428
RHSA-2026:61679
SUSE-SU-2026:23157-1
SUSE-SU-2026:23223-1
SUSE-SU-2026:23235-1
SUSE-SU-2026:3647-1

Affected Products

Rocky Linux
Open-Iscsi