CVE-2026-44944: iscsiuio control-socket authentication bypass in open-iscsi
An Incorrect Authorization vulnerability in open-iscsi allows unprivilidged local users to use the isscsiuio control socket.
This issue affects open-iscsi: from ? through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
Other sources
iscsiuio control-socket authentication bypass in open-iscsi
— Microsoft
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade to a fixed release to a version that resolves this vulnerability.
Fixed in 2.1.12-1
Event History
Frequently Asked Questions
What is the severity of CVE-2026-44944?
The severity of CVE-2026-44944 is high, rated at 8.5 on the CVSS scale.
What type of vulnerability is CVE-2026-44944?
CVE-2026-44944 is an Incorrect Authorization vulnerability that allows unprivileged local users to access the iscsuio control socket.
Which software is affected by CVE-2026-44944?
CVE-2026-44944 affects the open-iscsi software, specifically versions prior to commit 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
How do I fix CVE-2026-44944?
To fix CVE-2026-44944, update the open-iscsi software to the latest version that contains the patch.
Who is impacted by CVE-2026-44944?
Unprivileged local users are impacted by CVE-2026-44944 as they can exploit the vulnerability to access the control socket.