Executive brief
A vulnerability in the Oracle Solaris operating system's filesystem component allows a user with low-level access to compromise the system. An attacker could delete or modify critical system data and cause the entire server to crash or hang, leading to a total service outage. This impact can disrupt business operations and compromise the integrity of stored information.
Technical details
A vulnerability exists in the Filesystems component of Oracle Solaris 11.4. It is classified as an easily exploitable flaw that requires local logon credentials with low privileges. An attacker can exploit this to achieve unauthorized creation, deletion, or modification of critical system data or all data accessible to the OS. Additionally, the exploit can be used to trigger a hang or a frequently repeatable crash, resulting in a complete denial of service (DoS). The vulnerability is tracked as CVE-2026-60659 and was addressed in the Oracle Critical Patch Update for July 2026.
Affected products
- Oracle Solaris 11.4
Timeline
- 2026-07-21: disclosed
- 2026-07-21: advisory: Oracle July 2026 Critical Patch Update released.