Junglewise Threat Intelligence

CVE-2026-44944: open-iscsi incorrect authorization in iscsiuio control socket

CVE-2026-44944 · Severity: info · CVSS 8.5 · Published 2026-07-29

Technologies: Open-iSCSI Project Open-Iscsi. Vendors: Open-Iscsi, Open-iSCSI Project.

Executive brief

A security vulnerability has been identified in open-iscsi, a tool used to connect Linux systems to network storage. An unauthorized local user could gain control over the storage interface, potentially allowing them to disrupt storage services or access sensitive data. This could lead to a complete compromise of the system's storage operations and data integrity.

Technical details

An incorrect authorization vulnerability (CWE-863) exists in the iscsiuio component of open-iscsi. The issue stems from a failure to properly verify credentials on the control socket, specifically by failing to validate connections against the correct file descriptor. A local, unprivileged attacker can exploit this to interact with the iscsiuio control socket, which typically requires elevated privileges. This allows the attacker to drive the interface, potentially leading to unauthorized storage configuration or data access. The issue is addressed in commit 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e.

Affected products

  • open-iscsi open-iscsi up to commit 668ca1df9c9a1e9bdd5c999ae1d67c9c8909237e

Timeline

  • 2026-07-29: advisory
  • 2026-07-29: patched

References

Related threats