CVE-2026-44943 Details
Description
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record. This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
A path traversal vulnerability has been identified in open-iscsi, allowing remote man-in-the-middle attackers to create root-owned files outside the database directory and inject lines into the record. This issue affects open-iscsi versions prior to the commit 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
Users can update to the latest version of open-iscsi, where this vulnerability has been addressed. For SUSE users, the update is available through the SUSE Linux Enterprise 15 Service Pack 2, 15 Service Pack 3, 15 Service Pack 4, 15 Service Pack 5, 15 Service Pack 6, 15 Service Pack 7, and 15 Update channels.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No CVSS 3.x data is available for this CVE.
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 29, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44943 | [email protected] | |
| https://github.com/open-iscsi/open-iscsi/commit/668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-22 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 29, 2026 | CVE Modified | CISA-ADP |
| Jul 29, 2026 | New CVE Received | [email protected] |