Description
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7.8 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A vulnerability exists in the Oracle Solaris Filesystems component that can be exploited by a low‑privileged user who can log onto the system. The flaw allows the attacker to compromise Oracle Solaris entirely, leading to full loss of confidentiality, integrity and availability for the affected machine. The weakness is an improper access control over filesystem operations, making the system susceptible to takeover by users with local logon rights.

Affected Systems

Oracle Solaris 11.4 is affected. The vulnerability resides in the Filesystems component of this version. No other versions or product families are mentioned as impacted.

Risk and Exploitability

The CVSS v3.1 base score of 7.8 indicates a high‑severity issue. Exploitation requires only local logon, and the description notes that the attack is difficult to conduct, which is reflected in an EPSS score of less than 1%. The vulnerability is not listed in the CISA KEV catalog. The likely attack path is a local attacker leveraging login credentials to execute privileged filesystem commands and gain control of the operating system.

Generated by OpenCVE AI on August 2, 2026 at 21:24 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the Oracle Solaris 11.4 security patch released in the CPU Jul 2026 alert from the Oracle website.
  • Reboot the Solaris system after applying the patch to ensure the fix is fully enforced.
  • Restrict local logon accounts to strictly necessary administrators and review / enforce appropriate file permissions.
  • Monitor system logs for anomalous filesystem activity to detect attempts to exploit legacy paths if the patch is delayed.

Generated by OpenCVE AI on August 2, 2026 at 21:24 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Sat, 01 Aug 2026 05:45:00 +0000

Type Values Removed Values Added
Title Local Filesystem Access Control Vulnerability Allowing System Takeover

Mon, 27 Jul 2026 12:30:00 +0000

Type Values Removed Values Added
Title Low‑privileged Logon Exploit in Oracle Solaris Filesystem Allows System Takeover
Weaknesses CWE-284
CWE-862

Fri, 24 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-269
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low‑privileged Logon Exploit in Oracle Solaris Filesystem Allows System Takeover
Weaknesses CWE-284
CWE-862

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.8 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H).
First Time appeared Oracle
Oracle solaris
CPEs cpe:2.3:a:oracle:solaris:11.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle solaris
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:58.388Z

Reserved: 2026-07-08T15:51:55.576Z

Link: CVE-2026-60661

cve-icon Vulnrichment

Updated: 2026-07-24T19:23:27.048Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-02T21:30:04Z

Weaknesses
  • CWE-269

    Improper Privilege Management