CVE-2026-104117 PUBLISHED

Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP group membership

Assigner: illumos
Reserved: 01.10.2026 Published: 09.10.2026 Updated: 09.10.2026

A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c does not require the solaris.network.interface.config authorization for the IPMGMT_CMD_IPMP_UPDATE command, although its handler, ipmgmt_ipmp_update_handler(), writes to the persistent ipadm configuration when the IPMGMT_PERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P
CVSS Score: 1.9

Product Status

Vendor illumos
Product illumos-gate
Versions Default: unaffected
  • affected from a73be61a80f7331c35adfa540bcf8f1546ff1e33 to e8d3efa1c56e5f2b5368600a2baeb7b1d54a07f8 (excl.)
Vendor OmniOS
Product OmniOS
Versions Default: affected
  • affected from r151042 to r151054 (excl.)
  • affected from r151058 to r151058w (excl.)
  • affected from r151056 to r151056aw (excl.)
  • affected from r151054 to r151054bw (excl.)

Solutions

Update your illumos distribution to one that includes the fix for this issue.

Credits

  • Robert French finder
  • James Wynne III finder
  • Andy Fiddaman remediation developer

References

Problem Types

  • CWE-862 Missing Authorization CWE