CVE-2026-44943Disclosure

LOWCVSS 6.9 · MEDIUM

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Patch affected systems immediately

Recommended action window: Monitor and triage in normal cycle

NVD description

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers  to create root-owned files outside the database and inject lines into the record. This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.

0.5/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-22

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

AVAILABLE

Momentum

STABLE

Threat summary

  • Patch or workaround signal is available
  • 2 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Patch or workaround mentioned in 2 signals
  • Technical details provided in 2 signals
  • Disclosure: 2 classified signals
  • Peaked 1d ago at 1 mentions (2026-08-08); latest day: 1
  • 2 total mentions across 2 days

Deep dive

Activity timeline2 mentions / 2d
00111Mentions · 2026-08-08: 1Mentions · 2026-08-09: 1Patch / Workaround · 2026-08-08: 1Patch / Workaround · 2026-08-09: 1Technical Details · 2026-08-08: 1Technical Details · 2026-08-09: 108-0808-09
Signal classification1 categories
Disclosure
2100.0%
Referenced assets2 URLs
Full discourse2 posts
  • connect24h@connect24h
    Disclosure

    嫌な組み合わせだ。open-iscsiで、discovery経由のremote limited file-writeがroot権限で成立するCVE-2026-44943と、iscsiuioのcontrol socket認証回避CVE-2026-44944が公開された。 2件を一連の攻撃経路とはまだ断定できない。とはいえ、認証境界の欠陥とroot書込が同じ製品に並ぶ以上、組合せ可能性は要検証だ。私のLinux基盤も、open-iscsi導入有無、iscsiuioの稼働状態、discoveryの到達範囲、root所有ファイルの不審な変更を同じ調査票で追う。使っている組織は、影響版と修正版の確認を早めた方が良い。 ソース: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2026-44943

    Post summary

    Two newly disclosed CVEs—CVE‑2026‑44943 affecting open‑iscsi and CVE‑2026‑44944 affecting iscsuio—are described along with technical details, and the text advises users to verify affected and fixed versions.

    00011473
    5.7K followersView on X
  • Windows Forum@windowsforum
    Disclosure

    ⚠️ CVE-2026-44943 lets untrusted Open-iSCSI discovery trigger limited root-level file writes. Linux admins: isolate those targets—because “discovery” shouldn’t mean “welcome, attackers.” https://windowsforum.com/security-alerts.84/cve-2026-44943-open-iscsi-root-file-write-fix-pending.442021/?utm_source=x&utm_medium=social&utm_campaign=news_node84 #LinuxSecurity #OpenIscsi #Cve202644943 #IscsiDiscovery https://t.co/MOgxA8H1BJ

    Post summary

    The post alerts that CVE-2026-44943 allows untrusted Open-iSCSI discovery to perform limited root-level file writes, advises isolation of targets, and notes a fix is pending.

    0000048
    1.3K followersView on X

Explore more