Description
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data as well as unauthorized access to critical data or complete access to all Oracle Solaris accessible data. CVSS 3.1 Base Score 5.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N).
Published: 2026-01-20
Score: 5.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local Privilege Escalation
Action: Patch
AI Analysis

Impact

The vulnerability resides in a driver component of Oracle Solaris, allowing a high‑privileged local user to create, delete, or modify critical data, or gain full access to all Solaris‑accessible data. The weakness results in direct confidentiality and integrity compromise but no impact on availability. The CVSS vector indicates a local attack with low authentication complexity, requiring high privileges and human interaction from a user other than the attacker. The documented impacts are unauthorized data creation, deletion, modification, and unauthorized access to critical data.

Affected Systems

Oracle Corporation’s Solaris operating system, specifically version 11, is affected. The driver component is the precise target of the flaw and any installation of Solaris 11 within a corporate infrastructure exposes the environment to this risk.

Risk and Exploitability

The CVSS base score of 5.8 reflects moderate severity. Exploit probability per EPSS is very low, reported as less than 1%. The vulnerability is not listed in the CISA KEV catalog. Because the exploit requires a local high‑privileged foothold and user interaction with an unrelated user, the likelihood of successful attacks in the wild is limited, though the impact of success is substantial.

Generated by OpenCVE AI on April 18, 2026 at 19:55 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Obtain and install the latest Oracle Solaris security patch that addresses the driver flaw.
  • If a patch is not yet available, upgrade to a supported version of Solaris that eliminates the affected driver component.
  • Enforce least‑privilege policies and restrict physical access to systems so that only trusted administrators can log on with high privileges.

Generated by OpenCVE AI on April 18, 2026 at 19:55 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 18 Apr 2026 20:15:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Solaris Driver

Thu, 29 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:o:oracle:solaris:11:*:*:*:*:*:*:*

Wed, 21 Jan 2026 21:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 20 Jan 2026 22:15:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data as well as unauthorized access to critical data or complete access to all Oracle Solaris accessible data. CVSS 3.1 Base Score 5.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N).
First Time appeared Oracle
Oracle solaris
CPEs cpe:2.3:a:oracle:solaris:11:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle solaris
References
Metrics cvssV3_1

{'score': 5.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-02-26T14:44:40.733Z

Reserved: 2026-01-05T18:07:34.710Z

Link: CVE-2026-21935

cve-icon Vulnrichment

Updated: 2026-01-21T20:57:26.267Z

cve-icon NVD

Status : Analyzed

Published: 2026-01-20T22:15:56.160

Modified: 2026-01-29T21:11:22.673

Link: CVE-2026-21935

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-18T20:00:09Z

Weaknesses