A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c does not require the solaris.network.interface.config authorization for the IPMGMT_CMD_IPMP_UPDATE command, although its handler, ipmgmt_ipmp_update_handler(), writes to the persistent ipadm configuration when the IPMGMT_PERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.

Project Subscriptions

Vendors Products
Illumos Subscribe
Illumos-gate Subscribe
Advisories

No advisories yet.

Fixes

Solution

Update your illumos distribution to one that includes the fix for this issue.


Workaround

No workaround given by the vendor.

History

Fri, 09 Oct 2026 17:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Fri, 09 Oct 2026 17:00:00 +0000

Type Values Removed Values Added
First Time appeared Illumos
Illumos illumos-gate
Omnios
Omnios omnios
Vendors & Products Illumos
Illumos illumos-gate
Omnios
Omnios omnios

Fri, 09 Oct 2026 14:30:00 +0000

Type Values Removed Values Added
Description A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c does not require the solaris.network.interface.config authorization for the IPMGMT_CMD_IPMP_UPDATE command, although its handler, ipmgmt_ipmp_update_handler(), writes to the persistent ipadm configuration when the IPMGMT_PERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.
Title Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP group membership
Weaknesses CWE-862
References
Metrics cvssV4_0

{'score': 1.9, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: illumos

Published:

Updated: 2026-10-09T16:45:59.398Z

Reserved: 2026-10-01T18:07:53.956Z

Link: CVE-2026-104117

cve-icon Vulnrichment

Updated: 2026-10-09T16:15:23.379Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-10-09T15:17:07.910

Modified: 2026-10-09T17:16:44.960

Link: CVE-2026-104117

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-10-09T16:45:09Z

Weaknesses