CVE-2026-44943: remote limited file-write as root via discovery in open-iscsi
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record.
This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
Other sources
remote limited file-write as root via discovery in open-iscsi
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.1.12-1
Event History
Frequently Asked Questions
What is CVE-2026-44943?
CVE-2026-44943 is a Path Traversal vulnerability in open-iscsi that allows remote attackers to create root-owned files outside the intended directory.
What is the severity of CVE-2026-44943?
CVE-2026-44943 has a severity rating of medium, with a CVSS score of 6.9.
How do I fix CVE-2026-44943?
To fix CVE-2026-44943, ensure that you apply the latest patches or updates provided by the open-iscsi maintainers.
Who is affected by CVE-2026-44943?
CVE-2026-44943 affects users of open-iscsi from versions prior to the fix introduced in commit 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
What kind of attacks can exploit CVE-2026-44943?
CVE-2026-44943 can be exploited by remote Man-in-the-Middle (MITM) attackers to manipulate files and inject unauthorized content.