Description
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
Published: 2026-07-21
Score: 7 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The Oracle Solaris 11.4 Utility component contains a flaw that allows an attacker who can log in to the system with low privileges to elevate their credentials and gain complete control over the operating system. Successful exploitation would give the attacker unrestricted access to data, configuration, and all system functions, impacting confidentiality, integrity, and availability. The vulnerability is based on the CWE‑269: Improper Privilege Management.

Affected Systems

The flaw affects Oracle Solaris 11.4 only. No other releases or architectures are reported to contain the issue. Systems running this version that are exposed to local logons are susceptible.

Risk and Exploitability

The CVSS score of 7.0 indicates a high severity rating. The EPSS score of less than 1% suggests that current exploitation attempts are very rare, but the vulnerability remains exploitable by a local attacker with a valid login. As the flaw is not listed in CISA's KEV catalog, there are no publicly confirmed exploit campaigns. However, since the attack requires local credentials, any environment that allows user logons is at risk, and successful exploitation would allow the attacker to fully compromise the Solaris installation.

Generated by OpenCVE AI on August 4, 2026 at 02:36 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Solaris 11.4 patch released in the July 2026 CPU advisory
  • Restrict local user accounts to only those absolutely necessary and enforce least privilege to reduce available low‑privileged accounts
  • If a patch cannot be applied immediately, consider disabling or replacing the vulnerable utility component, or upgrade to a newer, supported Solaris release that no longer contains the flaw

Generated by OpenCVE AI on August 4, 2026 at 02:36 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Solaris 11.4 Utility Component

Thu, 30 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Local Privilege Escalation in Oracle Solaris 11.4 Utility Component

Tue, 28 Jul 2026 21:00:00 +0000

Type Values Removed Values Added
Title Low-Privilege Local Exploitation in Oracle Solaris 11.4 Utility Enables Full System Compromise
Weaknesses CWE-284

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Low-Privilege Local Exploitation in Oracle Solaris 11.4 Utility Enables Full System Compromise
Weaknesses CWE-269
CWE-284

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in takeover of Oracle Solaris. CVSS 3.1 Base Score 7.0 (Confidentiality, Integrity and Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H).
First Time appeared Oracle
Oracle solaris
CPEs cpe:2.3:a:oracle:solaris:11.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle solaris
References
Metrics cvssV3_1

{'score': 7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-28T03:56:59.169Z

Reserved: 2026-07-08T15:51:55.594Z

Link: CVE-2026-60833

cve-icon Vulnrichment

Updated: 2026-07-24T18:27:25.983Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:21.120

Modified: 2026-07-31T17:25:30.460

Link: CVE-2026-60833

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:45:02Z

Weaknesses
  • CWE-269

    Improper Privilege Management