SEPTEMBER 19, 2026
Live Feed
Back to database
Case File

CVE-2026-44943

MEDIUM · CVSS 6.9 EPSS 0.33% Public Exploit

Source: NVD + CISA KEV + EPSS · Published 2026-07-29 · Last synced 2026-08-28

CyberRota Analysis

AI-Generated

A path traversal vulnerability in open-iscsi allows remote man-in-the-middle (MITM) attackers to create root-owned files outside of the intended database, potentially leading to unauthorized access and data manipulation. Organizations using affected versions of open-iscsi should prioritize remediation to mitigate risks associated with unauthorized file creation and data integrity breaches.

Public Exploit Signal

A public exploit, PoC, GitHub repository or Metasploit reference was detected for this CVE.

GitHub PoC Links

Note: these links are listed for security research and verification purposes only.

CVE
CVE-2026-44943
Severity
MEDIUM
CVSS
6.9
EPSS
0.33%

Original NVD Description

An Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in open-iscsi allows remote MITM attackersĀ  to create root-owned files outside the database and inject lines into the record. This issue affects open-iscsi: from through 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.