CVE-2026-44943
remote limited file-write as root via discovery in open-iscsi
CVSS Score
0.0
EPSS Score
0.0%
EPSS Percentile
0th
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record. This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
| CWE | CWE-22 |
| Vendor | open-iscsi |
| Product | open-iscsi |
| Published | Jul 29, 2026 |
Stay Ahead of the Next One
Get instant alerts for open-iscsi open-iscsi
Be the first to know when new unknown vulnerabilities affecting open-iscsi open-iscsi are published — delivered to Slack, Telegram or Discord.
Get Free Alerts →
Free · No credit card · 60 sec setup
Affected Versions
open-iscsi / open-iscsi
? ≤ 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e
References
Credits
Keith at Linneman Labs