Impact
The vulnerability resides in the Utility component of Oracle Solaris 11.4, enabling a low‑privilege attacker with network access via RAD to obtain unauthorized access to critical data and, in accessible Solaris data, and permitting unauthorized update, insert, or delete operations on Solaris data sets. The CVSS 3.1 vector indicates a high confidentiality impact, low integrity impact, no availability impact, a scope change, and a high access complexity requirement.
Affected Systems
The affected product is Oracle Solaris 11.4 running the Utility component. Systems of this version are listed in the Oracle CPUJul2026 advisory; other Oracle products that depend on the same component may also be impacted.
Risk and Exploitability
The CVSS base score of 7.1 and an EPSS of less than 1% suggest a moderate likelihood of exploitation in the wild, and the vulnerability is not yet listed in the CISA KEV catalog. The attack vector requires network access, low privileges, and a high access complexity, which together allow an attacker to broaden access within the Solaris environment, potentially exposing or altering sensitive data.
OpenCVE Enrichment