Cyber Resilience

CVE-2026-21935

Oracle Solaris 11

Published
20 January 2026
Modified
29 January 2026
Patch / advisory
CVSS Score v3.1 5.8
Click a component to see what it means
Raw vectorCVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N
EPSS Score 0.0019 9th percentile
Risk Priority 39 floored blend · peak EPSS

Summary

CVE-2026-21935 is a medium-severity an unspecified weakness vulnerability in Oracle Solaris. Its CVSS base score is 5.8 (Medium).

Operationally, ranked at the 9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

The strongest mitigations our analysis identified map to AC-6 (Least Privilege) and SI-2 (Flaw Remediation) — see the control section below for these in your framework.

EU & UK References

Vulnerability Data

Vulnerability in the Oracle Solaris product of Oracle Systems (component: Driver). The supported version that is affected is 11. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Solaris executes to compromise Oracle Solaris. Successful…

more

attacks require human interaction from a person other than the attacker. Successful attacks of this vulnerability can result in unauthorized creation, deletion or modification access to critical data or all Oracle Solaris accessible data as well as unauthorized access to critical data or complete access to all Oracle Solaris accessible data. CVSS 3.1 Base Score 5.8 (Confidentiality and Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:R/S:U/C:H/I:H/A:N).

CWE(s)

Related Threats

MITRE ATT&CK Enterprise TechniquesAI

Insufficient information to map techniques.
Confidence: LOW · MITRE ATT&CK Enterprise v19.0

CVEs Like This One

CVE-2023-22129Same product: Oracle Solaris
CVE-2025-53070Same product: Oracle Solaris
CVE-2026-21942Same product: Oracle Solaris
CVE-2024-21059Same product: Oracle Solaris
CVE-2019-3010Same product: Oracle Solaris
CVE-2023-21928Same product: Oracle Solaris
CVE-2023-21900Same product: Oracle Solaris
CVE-2026-61202Same product: Oracle Solaris
CVE-2024-21151Same product: Oracle Solaris
CVE-2023-21948Same product: Oracle Solaris

Affected Assets

oracle
solaris
11

Mitigating Controls

Control response

Prevent
Stop it (NIST 800-53)
  • AC-6 Least Privilege
  • SI-2 Flaw Remediation
  • AC-3 Access Enforcement
Detect
Catch it (NIST detect / respond)

Harden
Shrink the surface (DISA STIG)

Validate
Prove the fix (OWASP ASVS)

Mitigating Controls (NIST 800-53 r5) AI

prevent

Limits the scope of high-privileged local accounts that can reach the vulnerable Solaris driver, directly reducing the attack surface described in the CVE.

prevent

Requires timely application of vendor patches that remediate the driver flaw before an attacker can exploit it.

prevent

Enforces access-control decisions inside the kernel/driver so that even an authenticated high-privileged user cannot arbitrarily create, modify or read critical data.

References