CVE-2026-46978

Oracle · Solaris

A critical vulnerability in the Oracle Solaris Remote Administration Daemon allows unauthenticated attackers to modify or delete critical system data via HTTPS.

Executive summary

An unauthenticated, critical vulnerability in Oracle Solaris allows remote attackers to manipulate or delete sensitive data without any user interaction.

Vulnerability

The Remote Administration Daemon in Solaris 11.4 lacks proper authentication checks, permitting an unauthenticated attacker with network access to perform unauthorized data modifications. The vulnerability is network-exploitable via HTTPS and carries a high risk of data integrity loss.

Business impact

With a CVSS score of 10.0, this flaw represents a significant risk to the integrity and confidentiality of critical Oracle Solaris systems. Successful exploitation could allow an attacker to destroy or alter sensitive business data, potentially causing irreversible service disruption and loss of critical information.

Remediation

Immediate Action: Apply the relevant security patch from the Oracle June 2026 Critical Security Patch Update to all Solaris 11.4 installations.

Proactive Monitoring: Review audit logs for unauthorized access attempts to the Remote Administration Daemon and monitor for unexpected modifications to critical system files.

Compensating Controls: Restrict access to the Remote Administration Daemon to trusted network ranges and ensure the service is not exposed to the public internet.

Exploitation status

Public Exploit Available: False

Analyst recommendation

Organizations running Oracle Solaris 11.4 must treat this vulnerability with the highest priority. Given the ease of exploitation and the potential for complete data compromise, patching should be scheduled immediately to maintain system integrity.