{"id":"CVE-2026-104117","title":"A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration","summary":"A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_doo…","severity":"none","cwe":["CWE-862"],"published":"2026-10-09","updated":"2026-10-09","sourceUpdated":"2026-10-09T17:16:44.960","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-104117","references":[{"url":"https://github.com/illumos/illumos-gate/commit/e8d3efa1c56e5f2b5368600a2baeb7b1d54a07f8","label":"0ca53633-f0b5-4853-ba72-e0a2e62000d0"},{"url":"https://illumos.org/issues/18492","label":"0ca53633-f0b5-4853-ba72-e0a2e62000d0"},{"url":"https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers","label":"0ca53633-f0b5-4853-ba72-e0a2e62000d0"}],"tags":["nvd"],"ingestedAt":"2026-10-09T16:02:33.376Z","slug":"CVE-2026-104117","body":"## Overview\n\nA missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c does not require the solaris.network.interface.config authorization for the IPMGMT_CMD_IPMP_UPDATE command, although its handler, ipmgmt_ipmp_update_handler(), writes to the persistent ipadm configuration when the IPMGMT_PERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"sunlit","depthScore":3,"depthScoreParts":{"impact":2.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}