HarborGuardharborguardDatabase
Back to search
CRITICALCVE-2026-46978Published Modified CNA oracle

CVE-2026-46978: Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon)

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Remote Administration Daemon). The supported version that is affected is 11.4. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTPS to compromise Oracle Solaris. While the vulnerability is in Oracle Solaris, attacks may significantly impact additional products (scope change). Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data as well as unauthorized access to critical data or complete access to all Oracle Solaris accessible data. CVSS 3.1 Base Score 10.0 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N).

Metrics

CVSS v3.1
10.0
Severity
CRITICAL
Fixed in
Affected Products
1

Get notified

Email me when this CVE is updated: new fix versions, severity changes, or any record change.

HarborGuard Analysis

Synopsis

This is a critical-severity authentication bypass and data compromise vulnerability in the Remote Administration Daemon (RAD) component of Oracle Solaris 11.4. An unauthenticated attacker with network access over HTTPS can reach the affected service with no prerequisites, no victim interaction, and no special knowledge of the target environment. Successful exploitation gives the attacker full read and write access to all data accessible by Oracle Solaris, and the impact crosses scope boundaries, meaning other products co-hosted with the affected system are also at risk. HarborGuard tracks this advisory and will make a patched-image rebuild available the moment Oracle publishes a fix.

HarborGuard Coverage

Detection

Detection is available across every HarborGuard environment: the CVE is ingested from upstream Oracle and NVD feeds within minutes of publication and matched against all customer images, including custom-built images that layer Oracle Solaris 11.4 components. Any image carrying the affected RAD package version is flagged immediately in the scan pipeline.

Available
Triage

HarborGuard scores this finding at CVSS 10.0 Critical and surfaces it at the highest severity tier in each customer environment. Per-environment compliance policy weighting is applied automatically, and the finding is routed to the security inbox or team configured by each customer organization.

Available
Patch

No fix version has been published by Oracle as of the CVE record date. HarborGuard re-evaluates the advisory on every ingest cycle and will make a patched-image rebuild available the moment an upstream fix is released. For customers with auto-remediation enabled, the rebuild, regression-test run, and PR against affected workloads will be triggered automatically at that point.

Pending upstream

Exploit Conditions

  • Network reachabilityRequired

    The attacker must reach the Remote Administration Daemon over the network via HTTPS; no local or physical access is required, but the service must be network-exposed.

  • AuthenticationNot required

    No credentials or account of any privilege level are needed; the attack can be launched anonymously over HTTPS.

  • Victim interactionNot required

    No user action, click, or social engineering is required; the attacker operates entirely without victim involvement.

  • Attack complexityDetail

    Attack complexity is Low, meaning the exploit is reliable and repeatable without needing to engineer race conditions, specific memory layouts, or other environmental dependencies.

Blast Radius

  • Reads all data accessible to Oracle Solaris, including stored credentials, configuration files, and application data.
  • Creates, modifies, or deletes critical data across the full Oracle Solaris data set, enabling persistent tampering or sabotage.
  • Because the CVSS scope is Changed, other products sharing the host or managed through RAD are also reachable by a successful attacker, extending the compromise beyond the Solaris instance itself.

How HarborGuard Handles This

Available on HarborGuard: because Oracle has not yet published a fix for this CVE, HarborGuard monitors the advisory on every ingest cycle and will trigger a patched-image rebuild automatically the moment an upstream fix version is released. For customers with auto-remediation enabled, that rebuild will be followed by a regression-test run and a PR opened against affected workloads. In the interim, compensating controls are strongly recommended: apply network-policy isolation to restrict HTTPS access to the RAD port to only trusted source addresses, enable egress filtering to limit lateral movement from any compromised Solaris host, and consider disabling or firewalling RAD entirely on hosts where remote administration is not operationally required. HarborGuard will surface this finding at Critical severity in every environment where an affected Oracle Solaris 11.4 image is detected, regardless of whether the image was pulled from a public registry or built internally.

See how HarborGuard automates this
Affected packages
  • Oracle Corporation / Oracle Solaris
    11.4
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
References