Description
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with network access via RAD to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Solaris accessible data as well as unauthorized update, insert or delete access to some of Oracle Solaris accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).
Published: 2026-07-21
Score: 7.1 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability resides in the Utility component of Oracle Solaris 11.4, enabling a low‑privilege attacker with network access via RAD to obtain unauthorized access to critical data and, in accessible Solaris data, and permitting unauthorized update, insert, or delete operations on Solaris data sets. The CVSS 3.1 vector indicates a high confidentiality impact, low integrity impact, no availability impact, a scope change, and a high access complexity requirement.

Affected Systems

The affected product is Oracle Solaris 11.4 running the Utility component. Systems of this version are listed in the Oracle CPUJul2026 advisory; other Oracle products that depend on the same component may also be impacted.

Risk and Exploitability

The CVSS base score of 7.1 and an EPSS of less than 1% suggest a moderate likelihood of exploitation in the wild, and the vulnerability is not yet listed in the CISA KEV catalog. The attack vector requires network access, low privileges, and a high access complexity, which together allow an attacker to broaden access within the Solaris environment, potentially exposing or altering sensitive data.

Generated by OpenCVE AI on August 4, 2026 at 02:35 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the Oracle Solaris 11.4 patch released in the Oracle CPUJul2026 advisory to address the Utility component flaw.
  • Restrict RAD‑related network paths and limit inbound connections to trusted hosts to reduce the attack surface for low‑privilege attackers.
  • Enforce least privilege for all users accessing Solaris data to limit unauthorized data modification attempts.
  • If a patch cannot be applied immediately, isolate or disconnect affected systems from untrusted networks as a temporary containment measure.

Generated by OpenCVE AI on August 4, 2026 at 02:35 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 03:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Exploit in Oracle Solaris 11.4 Utility Component

Thu, 30 Jul 2026 13:00:00 +0000

Type Values Removed Values Added
Title Low‑Privilege Network Exploit in Oracle Solaris 11.4 Utility Component

Wed, 29 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Mon, 27 Jul 2026 12:00:00 +0000

Type Values Removed Values Added
Title Privilege escalation in Oracle Solaris 11.4 via Utility component
Weaknesses CWE-285

Fri, 24 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-284
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Thu, 23 Jul 2026 22:45:00 +0000

Type Values Removed Values Added
Title Privilege escalation in Oracle Solaris 11.4 via Utility component
Weaknesses CWE-285

Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Solaris product of Oracle Systems (component: Utility). The supported version that is affected is 11.4. Difficult to exploit vulnerability allows low privileged attacker with network access via RAD to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized access to critical data or complete access to all Oracle Solaris accessible data as well as unauthorized update, insert or delete access to some of Oracle Solaris accessible data. CVSS 3.1 Base Score 7.1 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N).
First Time appeared Oracle
Oracle solaris
CPEs cpe:2.3:a:oracle:solaris:11.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle solaris
References
Metrics cvssV3_1

{'score': 7.1, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:L/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-29T19:26:41.334Z

Reserved: 2026-07-08T15:51:55.594Z

Link: CVE-2026-60834

cve-icon Vulnrichment

Updated: 2026-07-24T18:26:44.941Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-21T22:18:21.237

Modified: 2026-07-31T17:18:00.213

Link: CVE-2026-60834

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:45:02Z

Weaknesses