Description
Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
Published: 2026-07-21
Score: 5.5 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the filesystems component of Oracle Solaris allows a local attacker who possesses logon credentials and low privileges to force the operating system to hang or repeatedly crash. The vulnerability is exploitable without user interaction and directly impacts availability, terminating user sessions, stopping services, or requiring a reboot. The description indicates that the flaw is tied to filesystem operations, and it is inferred that this involves improper handling of those operations, which can lead to a complete denial of service.

Affected Systems

Oracle Solaris version 11.4 is affected by this issue; the vulnerability applies to any installation that has not applied the Oracle patch released in the July 2026 Critical Patch Update.

Risk and Exploitability

The CVSS v3.1 base score of 5.5 denotes a moderate severity, and the EPSS score of less than 1 % indicates a low probability of exploitation at the time of this analysis. The vulnerability is not listed in the CISA KEV catalog. Its local attack vector and low privilege requirements mean that only users with logon access to the system can leverage the flaw; the impact is isolated to availability of the affected Solaris instance.

Generated by OpenCVE AI on August 4, 2026 at 02:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Oracle Solaris patch or upgrade to a supported version that resolves CVE-2026-61052.
  • Restrict permissions for local user accounts to limit write access to filesystem paths that are vulnerable to the denial‑of‑service trigger.
  • Enable system monitoring or watchdog mechanisms to automatically recover from hangs or crashes, and review logs for repeated failures.

Generated by OpenCVE AI on August 4, 2026 at 02:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 04 Aug 2026 02:30:00 +0000

Type Values Removed Values Added
Title Oracle Solaris Local Filesystem Exploit Causes System Hang and Crash

Thu, 30 Jul 2026 12:15:00 +0000

Type Values Removed Values Added
Title Local Filesystem Denial of Service in Oracle Solaris 11.4

Sun, 26 Jul 2026 06:00:00 +0000

Type Values Removed Values Added
Title Local Filesystem Denial of Service in Oracle Solaris 11.4

Fri, 24 Jul 2026 18:30:00 +0000

Type Values Removed Values Added
Weaknesses CWE-400
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 21 Jul 2026 22:00:00 +0000

Type Values Removed Values Added
Description Vulnerability in the Oracle Solaris product of Oracle Systems (component: Filesystems). The supported version that is affected is 11.4. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful attacks of this vulnerability can result in unauthorized ability to cause a hang or frequently repeatable crash (complete DOS) of Oracle Solaris. CVSS 3.1 Base Score 5.5 (Availability impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H).
First Time appeared Oracle
Oracle solaris
CPEs cpe:2.3:a:oracle:solaris:11.4:*:*:*:*:*:*:*
Vendors & Products Oracle
Oracle solaris
References
Metrics cvssV3_1

{'score': 5.5, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H'}


cve-icon MITRE

Status: PUBLISHED

Assigner: oracle

Published:

Updated: 2026-07-24T14:23:52.364Z

Reserved: 2026-07-08T15:51:55.610Z

Link: CVE-2026-61052

cve-icon Vulnrichment

Updated: 2026-07-24T14:23:47.308Z

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T02:15:04Z

Weaknesses
  • CWE-400

    Uncontrolled Resource Consumption