Executive brief
A critical vulnerability has been identified in the Remote Administration Daemon of Oracle Solaris 11.4. This component is responsible for managing system configuration and administration tasks over the network. An attacker could exploit this flaw to gain full access to sensitive system data or modify critical files, potentially compromising the entire operating system and any applications running on it.
Technical details
An improper access control vulnerability (CWE-284) exists in the Remote Administration Daemon (RAD) component of Oracle Solaris 11.4. The flaw is easily exploitable over the network via HTTPS without requiring any user authentication or interaction. A successful exploit allows an attacker to achieve a 'scope change,' meaning the impact can extend beyond the Solaris OS to other integrated products. Attackers can gain unauthorized read, create, delete, or modification access to all data accessible by the operating system. While the CVSS vector indicates high confidentiality and integrity impacts, availability is not listed as being directly affected by the vulnerability itself.
Affected products
- Oracle Solaris 11.4
Timeline
- 2026-06-17: disclosed
- 2026-06-17: advisory