CVE-2026-104117
Received Received - Intake

BaseFortify

Vulnerability report for CVE-2026-104117, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-10-09

Last updated on: 2026-10-09

Assigner: illumos

Description

A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c does not require the solaris.network.interface.config authorization for the IPMGMT_CMD_IPMP_UPDATE command, although its handler, ipmgmt_ipmp_update_handler(), writes to the persistent ipadm configuration when the IPMGMT_PERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-10-09
Last Modified
2026-10-09
Generated
2026-10-09
AI Q&A
2026-10-09
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 5 associated CPEs
Vendor Product Version / Range
illumos illumos-gate a73be61a80f7331c35adfa540bcf8f1546ff1e33
OmniOS OmniOS r151042
OmniOS OmniOS r151058
OmniOS OmniOS r151056
OmniOS OmniOS r151054

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-862 The product does not perform an authorization check when an actor attempts to access a resource or perform an action.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is a missing authorization check in the illumos IP management daemon (ipmgmtd). It allows a local user to modify the persistent IP multipathing (IPMP) configuration without proper privileges. The flaw exists in the door dispatch table which does not enforce the required authorization for the IPMGMT_CMD_IPMP_UPDATE command, enabling unauthorized changes to stored network settings.

Detection Guidance

To detect this vulnerability, check if the ipmgmtd daemon is running and if the authorization check for IPMP updates is missing. Review the ipmgmt_door_info_tbl array in /usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c for the IPMGMT_CMD_IPMP_UPDATE command. If the authorization flag is set to B_FALSE, the system is vulnerable.

Impact Analysis

An attacker could add or remove network interfaces from IPMP groups in the stored configuration. This change only takes effect after a reboot or when the configuration is reapplied, potentially disrupting network connectivity. Since the flaw has existed since 2021, affected systems may have persistent unauthorized changes waiting to be activated.

Compliance Impact

This vulnerability does not directly affect compliance with GDPR or HIPAA as it involves unauthorized local configuration changes to network settings rather than data access or privacy violations. However, if the IPMP misconfiguration disrupts network connectivity or services, it could indirectly impact systems handling sensitive data, potentially leading to compliance issues depending on operational context.

Mitigation Strategies

Apply the latest illumos-gate commit e8d3efa1 or later to fix the missing authorization check in ipmgmtd. This ensures the solaris.network.interface.config authorization is required for IPMP configuration changes.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-104117. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart