Junglewise Threat Intelligence

CVE-2026-60661: Oracle Solaris privilege escalation in Filesystems

CVE-2026-60661 · Severity: high · CVSS 7.8 · Published 2026-07-21

Technologies: Oracle Solaris. Vendors: Oracle.

Executive brief

A security vulnerability exists in the Filesystems component of Oracle Solaris 11.4. A user with low-level access to the system could exploit this flaw to gain full control over the operating system. This could lead to a total loss of data confidentiality and system availability, potentially impacting other services running on the same infrastructure.

Technical details

A vulnerability in the Filesystems component of Oracle Solaris version 11.4 allows for a complete system takeover. The exploit requires the attacker to have local logon credentials with low privileges. While the attack is characterized as difficult to execute (High Attack Complexity), a successful exploit results in a scope change, meaning the impact can extend beyond Solaris to other products or layers of the infrastructure. The vulnerability affects the confidentiality, integrity, and availability of the system. Users are advised to refer to the Oracle July 2026 Critical Patch Update for remediation details.

Affected products

  • Oracle Solaris 11.4

Timeline

  • 2026-07-21: disclosed
  • 2026-07-21: advisory: Published by Oracle and NVD

References

Related threats