{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","feed_url":"https://feed.craftedsignal.io/vendors/open-iscsi/feed.json","home_page_url":"https://feed.craftedsignal.io/","items":[{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-44944"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["iscsiuio"],"_cs_severities":["medium"],"_cs_tags":[],"_cs_type":"advisory","_cs_vendors":["Open-iSCSI"],"content_html":"\u003cp\u003eThe iscsiuio component of the Open-iSCSI project contains an authentication bypass vulnerability identified as CVE-2026-44944. The flaw exists within the implementation of the control-socket, which fails to properly authenticate requests. An unauthorized local attacker can leverage this weakness to interact directly with the control socket, potentially executing commands or modifying system state associated with iSCSI operations. This vulnerability poses a risk to systems relying on iSCSI storage, as it allows for privilege escalation or unauthorized control over storage connectivity by a local process or user. Defenders should prioritize updating Open-iSCSI packages to versions that implement proper socket-level authentication.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows a local user to bypass security controls and perform unauthorized operations within the iscsiuio service, potentially leading to unauthorized storage access or disruption of iSCSI services.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpdate the Open-iSCSI package to the latest version provided by your Linux distribution to remediate CVE-2026-44944.\u003c/li\u003e\n\u003cli\u003eReview local system access logs to identify unauthorized attempts to communicate with the iscsiuio control socket.\u003c/li\u003e\n\u003cli\u003eApply the principle of least privilege to restrict access to the control socket if the application architecture permits.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-08T09:32:22Z","date_published":"2026-08-08T09:32:22Z","id":"https://feed.craftedsignal.io/briefs/2026-08-iscsiuio-auth-bypass/","summary":"CVE-2026-44944 describes an authentication bypass vulnerability in the Open-iSCSI iscsiuio control socket that allows local attackers to perform unauthorized actions.","title":"Authentication Bypass in Open-iSCSI iscsiuio Control Socket","url":"https://feed.craftedsignal.io/briefs/2026-08-iscsiuio-auth-bypass/"},{"_cs_actors":[],"_cs_cpes":[],"_cs_cves":[{"id":"CVE-2026-55995"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["open-iscsi"],"_cs_severities":["high"],"_cs_tags":["vulnerability","linux","privilege-escalation"],"_cs_type":"advisory","_cs_vendors":["open-iscsi"],"content_html":"\u003cp\u003eThe open-iscsi package contains a double-free vulnerability (CVE-2026-55995) located within its iSNS (Internet Storage Name Service) attribute decoder. A double-free occurs when an application attempts to free memory that has already been deallocated, which can lead to heap corruption and potentially allow an attacker to trigger an application crash or execute arbitrary code under specific conditions. This vulnerability impacts systems utilizing open-iscsi for iSCSI target and initiator connectivity. Defenders should prioritize patching systems running vulnerable versions of open-iscsi to mitigate the risk of denial-of-service or potential exploitation.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eThe vulnerability potentially allows for application instability, memory corruption, or service denial of the iSCSI service. If successfully exploited, this could disrupt storage connectivity for services relying on iSCSI, impacting enterprise infrastructure that depends on network-attached storage or storage area networks (SAN).\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003cul\u003e\n\u003cli\u003eUpgrade the open-iscsi package to the latest version provided by the distribution vendor to remediate CVE-2026-55995.\u003c/li\u003e\n\u003cli\u003eReview package management logs or inventory tools to identify systems running older versions of open-iscsi.\u003c/li\u003e\n\u003cli\u003eMonitor for unexpected service restarts of the open-iscsi daemon, as this may indicate an attempt to trigger the vulnerability or general instability.\u003c/li\u003e\n\u003c/ul\u003e\n","date_modified":"2026-08-08T09:32:17Z","date_published":"2026-08-08T09:32:10Z","id":"https://feed.craftedsignal.io/briefs/2026-08-open-iscsi-isns-vulnerability/","summary":"A double-free vulnerability exists in the iSNS attribute decoder of the open-iscsi package, which may lead to memory corruption or application instability.","title":"Double-free Vulnerability in open-iscsi iSNS Attribute Decoder","url":"https://feed.craftedsignal.io/briefs/2026-08-open-iscsi-isns-vulnerability/"}],"language":"en","title":"CraftedSignal Threat Feed - Open-ISCSI","version":"https://jsonfeed.org/version/1.1"}