Junglewise Threat Intelligence

CVE-2026-46914: Oracle Solaris privilege escalation and DoS in Filesystem

CVE-2026-46914 · Severity: high · CVSS 7.1 · Published 2026-06-17

Technologies: Oracle Solaris. Vendors: Oracle.

Executive brief

A vulnerability exists in the filesystem component of Oracle Solaris 11.4, a widely used enterprise operating system. A user with basic access to the system can exploit this flaw to view sensitive files they should not be able to see or crash the entire system, leading to a total service outage. This could result in the theft of confidential business data or significant operational downtime.

Technical details

This vulnerability is classified under Improper Privilege Management (CWE-269) and Uncontrolled Resource Consumption (CWE-400) within the Oracle Solaris Filesystem component. It is easily exploitable by a low-privileged attacker who has local logon access to the infrastructure. Successful exploitation allows the attacker to bypass standard access controls to read all Solaris-accessible data or trigger a kernel hang or repeatable crash, resulting in a complete denial-of-service (DoS). The attack does not require user interaction or high privileges. Oracle has addressed this in the June 2026 Critical Patch Update.

Affected products

  • Oracle Solaris 11.4

Timeline

  • 2026-06-17: disclosed
  • 2026-06-17: advisory: Oracle June 2026 Critical Patch Update released

References

Related threats