🟠 High | Source: Microsoft Security Response Center
CVE-2026-44944 is an authentication bypass vulnerability in iscsiuio, a component of the open-iscsi package used to manage iSCSI storage connections via a control socket. An attacker able to reach the control socket could bypass authentication and interact with the service without valid credentials. This is relevant to Azure environments where Linux VMs use iSCSI-based storage, as exploitation could allow unauthorised control over storage connectivity.
Security Architect’s Take: Audit Linux-based Azure VMs and node pools (including AKS) for open-iscsi installations and apply vendor patches immediately. Restrict access to the iscsiuio control socket using host-based firewall rules or strict file permissions to limit exposure whilst patching is under way.
Original advisory: CVE-2026-44944 iscsiuio control-socket authentication bypass in open-iscsi