Open-iSCSI: Trio of Critical Flaws Including Privilege Escalation Disclosed Together
Key findings • Three important vulnerabilities in Open-iSCSI disclosed on July 29, 2026. • CVE-2026-44943 allows privilege escalation via path traversal. • CVE-2026-44944 bypasses authent…
Key findings
- Three important vulnerabilities in Open-iSCSI disclosed on July 29, 2026.
- CVE-2026-44943 allows privilege escalation via path traversal.
- CVE-2026-44944 bypasses authentication in the iscsiuio control socket.
- CVE-2026-55995 causes denial of service via a double-free in iSNS decoding.
On July 29, 2026, a batch of three important vulnerabilities affecting Open-iSCSI was disclosed, presenting significant risks to users of the storage networking software. The vulnerabilities, detailed by the Open-iSCSI project, include a denial-of-service flaw, an authentication bypass, and a privilege escalation vulnerability, all stemming from issues within the iSNS (Internet Storage Name Service) attribute decoding and the iscsiuio control socket. The clustered disclosure highlights a critical window for administrators to update their systems.
The most severe of the disclosed vulnerabilities is CVE-2026-44943, a privilege escalation flaw that allows an attacker to gain elevated permissions on a vulnerable system through path traversal. This could enable an attacker to execute arbitrary code or modify system files, leading to a complete compromise.
Another critical vulnerability, CVE-2026-44944, presents an authentication bypass in the iscsiuio control socket. This could allow an unauthenticated attacker to gain unauthorized access to sensitive storage resources or control functions, potentially leading to data breaches or system manipulation.
Rounding out the batch is CVE-2026-55995, a denial-of-service vulnerability caused by a double-free error in the iSNS attribute decoder. Successful exploitation of this flaw could crash the Open-iSCSI service, rendering storage resources unavailable to legitimate users and disrupting operations.
All three vulnerabilities were disclosed on the same day, indicating a coordinated disclosure event. Users of Open-iSCSI are strongly advised to review the security advisories from the Open-iSCSI project and apply any available patches or mitigations as soon as possible to protect their environments from these critical security risks. The timely patching of these issues is crucial to prevent potential exploitation and maintain the integrity and availability of storage systems.