CVE-2026-44943
Severity CVSS v4.0:
MEDIUM
Type:
CWE-22
Path Traversal
Publication date:
29/07/2026
Last modified:
29/07/2026
Description
An Improper Limitation of a Pathname to a Restricted Directory (&#39;Path Traversal&#39;) vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record.<br />
<br />
<br />
<br />
<br />
<br />
<br />
This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
Impact
Base Score 4.0
6.90
Severity 4.0
MEDIUM



