Instituto Nacional de ciberseguridad. Sección Incibe
Instituto Nacional de Ciberseguridad. Sección INCIBE-CERT

CVE-2026-44943

Gravedad CVSS v4.0:
MEDIA
Tipo:
CWE-22 Limitación incorrecta de nombre de ruta a un directorio restringido (Path Traversal)
Fecha de publicación:
29/07/2026
Última modificación:
29/07/2026

Descripción

*** Pendiente de traducción *** An Improper Limitation of a Pathname to a Restricted Directory (&amp;#39;Path Traversal&amp;#39;) vulnerability in open-iscsi allows remote MITM attackers  to create root-owned files outside the database and inject lines into the record.<br /> <br /> <br /> <br /> <br /> <br /> <br /> This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.