Medium severityNVD Advisory· Published Jul 29, 2026· Updated Jul 30, 2026
CVE-2026-44943
CVE-2026-44943
Description
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record.
This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
6- Range: through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e
- osv-coords5 versionspkg:rpm/almalinux/iscsi-initiator-utilspkg:rpm/almalinux/iscsi-initiator-utils-iscsiuiopkg:rpm/almalinux/python3-iscsi-initiator-utilspkg:rpm/opensuse/open-iscsi&distro=openSUSE%20Leap%2016.0pkg:rpm/opensuse/open-iscsi&distro=openSUSE%20Tumbleweed
< 6.2.1.11-1.git4b3e853.el9_8.2+ 4 more
- (no CPE)range: < 6.2.1.11-1.git4b3e853.el9_8.2
- (no CPE)range: < 6.2.1.11-1.git4b3e853.el9_8.2
- (no CPE)range: < 6.2.1.11-1.git4b3e853.el9_8.2
- (no CPE)range: < 2.1.12-160000.4.1
- (no CPE)range: < 2.1.12-112.1
Patches
Vulnerability mechanics
References
2News mentions
1- Open-iSCSI: Trio of Critical Flaws Including Privilege Escalation Disclosed TogetherVypr Intelligence · Jul 29, 2026