Description
An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers  to create root-owned files outside the database and inject lines into the record.






This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
Published: 2026-07-29
Score: 6.9 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper limitation of a pathname that allows path traversal. Based on the description, it is inferred that an attacker who can mount a man‑in‑the‑middle on the iSCSI discovery process can create, modify, or delete files outside the intended database directory as the root user. This root‑owned file write can be leveraged to inject malicious configuration or execute arbitrary code, thereby compromising integrity and confidentiality of the system.

Affected Systems

The affected product is open-iscsi from the open-iscsi package. All releases up to and including the commit 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e are vulnerable. This includes any version that contains the code before the commit that fixes the path handling.

Risk and Exploitability

The CVSS score of 6.9 indicates a medium severity but the EPSS score of < 1% shows that exploitation is currently considered unlikely. The likely attack vector is an adversary positioning themselves in the iSCSI discovery network path, which might be limited to trusted internal networks. Because the flaw enables the creation of root‑owned files, it carries a high impact if an adversary succeeds.

Generated by OpenCVE AI on August 2, 2026 at 07:57 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade open-iscsi to a version released after commit 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e, which contains the fix for the path traversal issue.
  • Disable or restrict iSCSI discovery on networks where it is not required, limiting the surface for a man‑in‑the‑middle to influence the transaction.
  • Apply network segmentation or firewall rules to expose the iSCSI service only to trusted hosts, thereby reducing the opportunity for an attacker to interfere with the discovery phase.

Generated by OpenCVE AI on August 2, 2026 at 07:57 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 30 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
First Time appeared Open-iscsi Project
Open-iscsi Project open-iscsi
Vendors & Products Open-iscsi Project
Open-iscsi Project open-iscsi

Thu, 30 Jul 2026 00:15:00 +0000

Type Values Removed Values Added
References
Metrics threat_severity

None

cvssV3_1

{'score': 8.6, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:N/I:H/A:N'}

threat_severity

Important


Wed, 29 Jul 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Wed, 29 Jul 2026 13:15:00 +0000

Type Values Removed Values Added
Description An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackers  to create root-owned files outside the database and inject lines into the record. This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.
Title remote limited file-write as root via discovery in open-iscsi
Weaknesses CWE-22
References
Metrics cvssV4_0

{'score': 6.9, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:L/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Open-iscsi Project Open-iscsi
cve-icon MITRE

Status: PUBLISHED

Assigner: suse

Published:

Updated: 2026-07-29T14:00:28.582Z

Reserved: 2026-05-08T12:29:48.968Z

Link: CVE-2026-44943

cve-icon Vulnrichment

Updated: 2026-07-29T14:00:24.955Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-29T13:18:45.967

Modified: 2026-07-30T16:43:03.817

Link: CVE-2026-44943

cve-icon Redhat

Severity : Important

Publid Date: 2026-07-29T12:58:49Z

Links: CVE-2026-44943 - Bugzilla

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T08:00:04Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')