CVE-2026-104117

Source
https://cve.org/CVERecord?id=CVE-2026-104117
Import Source
https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104117.json
JSON Data
https://api.osv.dev/v1/vulns/CVE-2026-104117
Published
2026-10-09T14:15:42Z
Modified
2026-10-10T07:06:15Z
Severity
  • 1.9 (Low) CVSS_V4 - CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P CVSS Calculator
Summary
Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP group membership
Details

A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c does not require the solaris.network.interface.config authorization for the IPMGMT_CMD_IPMP_UPDATE command, although its handler, ipmgmt_ipmp_update_handler(), writes to the persistent ipadm configuration when the IPMGMT_PERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.

Database specific
{
    "cna_assigner": "illumos",
    "cwe_ids": [
        "CWE-862"
    ],
    "osv_generated_from": "https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104117.json",
    "unresolved_ranges": [
        {
            "extracted_events": [
                {
                    "introduced": "r151058"
                },
                {
                    "fixed": "r151058w"
                },
                {
                    "introduced": "r151056"
                },
                {
                    "fixed": "r151056aw"
                },
                {
                    "introduced": "r151054"
                },
                {
                    "fixed": "r151054bw"
                },
                {
                    "introduced": "r151042"
                },
                {
                    "fixed": "r151054"
                }
            ],
            "source": "AFFECTED_FIELD"
        }
    ]
}
References

Affected packages

Git / github.com/illumos/illumos-gate

Affected ranges

Type
GIT
Repo
https://github.com/illumos/illumos-gate
Events

Database specific

source
"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104117.json"
vanir_signatures
[
    {
        "deprecated": false,
        "digest": {
            "line_hashes": [
                "126661431725586066659286539593507849624",
                "204052327217988972666796062264515825142",
                "143976005806545626787265033609411117799",
                "144113481758427358405823741749584610013",
                "131069659055301147856225509726356473574"
            ],
            "threshold": 0.9
        },
        "id": "CVE-2026-104117-9e2dd23f",
        "signature_type": "Line",
        "signature_version": "v1",
        "source": "https://github.com/illumos/illumos-gate/commit/e8d3efa1c56e5f2b5368600a2baeb7b1d54a07f8",
        "target": {
            "file": "usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c"
        }
    }
]
vanir_signatures_modified
"2026-10-10T07:06:15Z"