CVE-2026-44943: Open-Iscsi
Medium severity, CVSS 6.9. EPSS: 0.6% chance of exploitation in the next 30 days.
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record. This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
Affected products
- Open-Iscsi Open-Iscsi
Published 2026-07-29. Last modified 2026-07-30.