Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1359 CNY

100%

CVE-2026-104117— Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP group membership

Quick assessment

Affected
illumos illumos-gate
Exploitation
No confirmed in-the-wild exploitation; assess based on exposure
Recommended action
Check the vendor advisory and references for a fixed version. If immediate upgrade is impossible, restrict exposure and increase monitoring.

illumos 的 IP 管理守护进程(ipmgmtd)中存在一项缺失的授权检查漏洞,允许本地用户更改持久化 IP 多路径(IPMP)配置。具体而言,在文件 中的 ipmgmtd 门分发表里, 命令未要求 授权,尽管其处理函数 在设置 标志时会写入持久化的 配置。因此,无特权的本地用户可以将接口添加至现有的 IPMP 组,或将其从现有的 IPMP 组中移除。该操作不会立即更改运行时的配置,而是在下次应用存储的配置(例如系统启动时)才生效,可能导致网络连通性中断。该漏洞自 2021 年(illumos-gate 提交

CVSS 1.9 · Low

Affected Version Matrix 5

VendorProduct Version RangeStatus
illumos illumos-gate a73be61a80f7331c35adfa540bcf8f1546ff1e33< e8d3efa1c56e5f2b5368600a2baeb7b1d54a07f8 affected
OmniOS OmniOS r151042< r151054 affected
r151058< r151058w affected
r151056< r151056aw affected
r151054< r151054bw affected
Get alerts for future matching vulnerabilities Log in to subscribe

I. Basic Information for CVE-2026-104117

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP group membership
Source: CVE Program / CVE List V5
Vulnerability Description
A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c does not require the solaris.network.interface.config authorization for the IPMGMT_CMD_IPMP_UPDATE command, although its handler, ipmgmt_ipmp_update_handler(), writes to the persistent ipadm configuration when the IPMGMT_PERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.
Source: CVE Program / CVE List V5
CVSS Information
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
Source: CVE Program / CVE List V5
Vulnerability Type
授权机制缺失
Source: CVE Program / CVE List V5

Affected Products

Vendor Product Affected Versions CPE Subscribe
illumos illumos-gate a73be61a80f7331c35adfa540bcf8f1546ff1e33 ~ e8d3efa1c56e5f2b5368600a2baeb7b1d54a07f8 -
OmniOS OmniOS r151042 ~ r151054 -

II. Public POCs for CVE-2026-104117

# POC Description Source Link Shenlong Link
AI-Generated POC Premium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2026-104117

请登录查看更多情报信息。

Patches & Fixes for CVE-2026-104117 (1)

Vendor Advisories for CVE-2026-104117 (2)

Same Patch Batch · illumos · 2026-10-09 · 6 CVEs total

CVE-2026-102916 6.8 MEDIUM Reachable assertion in illumos bhyve REP string instruction emulation allows guest to pani
CVE-2026-104112 6.8 MEDIUM Missing release of passed file descriptors in illumos nscd allows local users to exhaust k
CVE-2026-104114 5.4 MEDIUM NULL pointer dereference in illumos nwamd door handler allows local users to crash the dae
CVE-2026-104115 5.4 MEDIUM Stack buffer overflow in illumos reparsed nfs-basic plugin allows local users to crash the
CVE-2026-104116 1.9 LOW Missing authorization in illumos zonestatd allows local users to disrupt zonestat and enum

IV. Related Vulnerabilities

V. Comments for CVE-2026-104117

No comments yet


Leave a comment