Description
A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c does not require the solaris.network.interface.config authorization for the IPMGMT_CMD_IPMP_UPDATE command, although its handler, ipmgmt_ipmp_update_handler(), writes to the persistent ipadm configuration when the IPMGMT_PERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.
Published: 2026-10-09
Score: 1.9 Low
EPSS: n/a
KEV: No
Impact: Modification of Persistent IPMP Configuration
Action: Patch
AI Analysis

Impact

A missing authorization check in the illumos IP management daemon (ipmgmtd) allows an unprivileged local user to modify the persistent IP multipathing (IPMP) configuration by adding or removing interfaces from IPMP groups. The change does not affect the running configuration until the stored configuration is next applied, such as at boot, which may disrupt network connectivity. This vulnerability involves improper authorization (CWE-862) and does not enable remote code execution or immediate availability impact.

Affected Systems

All illumos distributions prior to commit e8d3efa1 in illumos-gate are affected, including OmniOS and illumos-gate. Versions from before this commit remain vulnerable; any distribution that includes the older commit a73be61a or earlier is impacted.

Risk and Exploitability

The CVSS score is 1.9, indicating a low severity. The EPSS score is not available and the issue is not listed in the CISA KEV catalog. The attack requires local user privileges and can alter persistent network configuration, potentially causing connectivity loss during the next boot. While the risk is low, it can affect local administrators without requiring network exposure.

Generated by OpenCVE AI on October 9, 2026 at 15:43 UTC.

Remediation

Vendor Solution

Update your illumos distribution to one that includes the fix for this issue.


OpenCVE Recommended Actions

  • Update your illumos distribution to a release that includes the fix for this issue. (The patch is in commit e8d3efa1.)
  • If an immediate system update is not possible, disable the ipmgmtd door service to prevent local users from modifying the IPMP configuration until the patch is applied.
  • After applying the update or disabling the service, reboot the system so that the persistent IPMP configuration can be reloaded safely.

Generated by OpenCVE AI on October 9, 2026 at 15:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Fri, 09 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c does not require the solaris.network.interface.config authorization for the IPMGMT_CMD_IPMP_UPDATE command, although its handler, ipmgmt_ipmp_update_handler(), writes to the persistent ipadm configuration when the IPMGMT_PERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.
Title Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP group membership
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 1.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: illumos

Published:

Updated: 2026-10-09T16:45:59.398Z

Reserved: 2026-10-01T18:07:53.956Z

Link: CVE-2026-104117

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-09T15:17:07.910

Modified: 2026-10-09T16:35:35.900

Link: CVE-2026-104117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T15:45:07Z

Weaknesses