Executive brief
A vulnerability exists in the filesystem component of Oracle Solaris 11.4, a widely used enterprise operating system. A user with basic access to the system can exploit this flaw to view sensitive files they should not be able to see or crash the entire system, leading to a total service outage. This could result in the theft of confidential business data or significant operational downtime.
Technical details
This vulnerability is classified under Improper Privilege Management (CWE-269) and Uncontrolled Resource Consumption (CWE-400) within the Oracle Solaris Filesystem component. It is easily exploitable by a low-privileged attacker who has local logon access to the infrastructure. Successful exploitation allows the attacker to bypass standard access controls to read all Solaris-accessible data or trigger a kernel hang or repeatable crash, resulting in a complete denial-of-service (DoS). The attack does not require user interaction or high privileges. Oracle has addressed this in the June 2026 Critical Patch Update.
Affected products
- Oracle Solaris 11.4
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory: Oracle June 2026 Critical Patch Update released