{"id":"CVE-2026-104117","summary":"Missing authorization in illumos ipmgmtd allows local users to change persistent IPMP group membership","details":"A missing authorization check in the illumos IP management daemon (ipmgmtd) allows a local user to change the persistent IP multipathing (IPMP) configuration. The ipmgmtd door dispatch table in usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c does not require the solaris.network.interface.config authorization for the IPMGMT_CMD_IPMP_UPDATE command, although its handler, ipmgmt_ipmp_update_handler(), writes to the persistent ipadm configuration when the IPMGMT_PERSIST flag is set. An unprivileged local user can therefore add interfaces to, or remove them from, existing IPMP groups in the stored configuration. The running configuration is not changed; the modification takes effect when the stored configuration is next applied, such as at boot, and may disrupt network connectivity. The flaw has existed since 2021 (illumos-gate commit a73be61a), and affects any illumos distribution prior to illumos-gate commit e8d3efa1.","modified":"2026-10-10T07:06:15.454929900Z","published":"2026-10-09T14:15:42.585Z","database_specific":{"osv_generated_from":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104117.json","unresolved_ranges":[{"source":"AFFECTED_FIELD","extracted_events":[{"introduced":"r151058"},{"fixed":"r151058w"},{"introduced":"r151056"},{"fixed":"r151056aw"},{"introduced":"r151054"},{"fixed":"r151054bw"},{"introduced":"r151042"},{"fixed":"r151054"}]}],"cna_assigner":"illumos","cwe_ids":["CWE-862"]},"references":[{"type":"ADVISORY","url":"https://github.com/CVEProject/cvelistV5/tree/main/cves/2026/104xxx/CVE-2026-104117.json"},{"type":"PACKAGE","url":"https://github.com/illumos/illumos-gate"},{"type":"FIX","url":"https://github.com/illumos/illumos-gate/commit/e8d3efa1c56e5f2b5368600a2baeb7b1d54a07f8"},{"type":"WEB","url":"https://illumos.org"},{"type":"REPORT","url":"https://illumos.org/issues/18492"},{"type":"ARTICLE","url":"https://illumos.topicbox.com/groups/developer/T3b859664594b7762/cve-2026-104112-to-cve-2026-104117-denial-of-service-and-missing-authorization-in-door-servers"},{"type":"ADVISORY","url":"https://nvd.nist.gov/vuln/detail/CVE-2026-104117"}],"affected":[{"ranges":[{"type":"GIT","repo":"https://github.com/illumos/illumos-gate","events":[{"introduced":"a73be61a80f7331c35adfa540bcf8f1546ff1e33"},{"fixed":"e8d3efa1c56e5f2b5368600a2baeb7b1d54a07f8"}]}],"database_specific":{"source":"https://storage.googleapis.com/cve-osv-conversion/osv-output/CVE-2026-104117.json","vanir_signatures":[{"id":"CVE-2026-104117-9e2dd23f","signature_type":"Line","signature_version":"v1","source":"https://github.com/illumos/illumos-gate/commit/e8d3efa1c56e5f2b5368600a2baeb7b1d54a07f8","target":{"file":"usr/src/cmd/cmd-inet/lib/ipmgmtd/ipmgmt_door.c"},"deprecated":false,"digest":{"line_hashes":["126661431725586066659286539593507849624","204052327217988972666796062264515825142","143976005806545626787265033609411117799","144113481758427358405823741749584610013","131069659055301147856225509726356473574"],"threshold":0.9}}],"vanir_signatures_modified":"2026-10-10T07:06:15Z"}}],"schema_version":"1.9.0","severity":[{"type":"CVSS_V4","score":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:L/VA:L/SC:N/SI:N/SA:N/E:P"}]}