Vulnerability Description
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject lines into the record. This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
Related Weaknesses (CWE)
References
- https://bugzilla.suse.com/show_bug.cgi?id=CVE-2026-44943
- https://github.com/open-iscsi/open-iscsi/commit/668ca1df9c9a1e9bdd5c999ae1d67c9c
FAQ
What is CVE-2026-44943?
CVE-2026-44943 is a documented vulnerability. An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers to create root-owned files outside the database and inject l...
How severe is CVE-2026-44943?
CVSS scoring is not yet available for CVE-2026-44943. Check NVD for updates.
Is there a patch for CVE-2026-44943?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.