Missing Authorization Check in illumos IP Management Daemon Affects Network Configuration
CVE-2026-104117

1.9LOW

Key Information:

Vendor

Illumos

Vendor
CVE Published:
9 October 2026

What is CVE-2026-104117?

The illumos IP management daemon (ipmgmtd) contains a vulnerability due to a missing authorization check that permits local users to alter the persistent IP multipathing (IPMP) configuration. This flaw occurs within the door dispatch table where necessary authorization for the IPMGMT_CMD_IPMP_UPDATE command is not enforced. As a result, unprivileged local users can manipulate IPMP group memberships in the stored configuration, which may lead to potential disruptions in network connectivity upon the next application of the stored configuration, such as during a reboot. This issue has persisted since 2021 and impacts all illumos distributions prior to the relevant patch.

Affected Version(s)

illumos-gate x86 a73be61a80f7331c35adfa540bcf8f1546ff1e33

OmniOS r151042

OmniOS r151042

References

CVSS V4

Score:
1.9
Severity:
LOW
Confidentiality:
None
Integrity:
Low
Availability:
Low
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Robert French
James Wynne III
Andy Fiddaman
.