CVE-2026-21930: Low severity Oracle ZFS Storage Appliance Kit vulnerability
Vulnerability in the Oracle ZFS Storage Appliance Kit product of Oracle Systems (component: Filesystems). The supported version that is affected is 8.8. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle ZFS Storage Appliance Kit executes to compromise Oracle ZFS Storage Appliance Kit. Successful attacks of this vulnerability can result in unauthorized update, insert or delete access to some of Oracle ZFS Storage Appliance Kit accessible data. CVSS 3.1 Base Score 2.3 (Integrity impacts). CVSS Vector: (CVSS:3.1/AV:L/AC:L/PR:H/UI:N/S:U/C:N/I:L/A:N).
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-21930?
CVE-2026-21930 has been rated as easily exploitable, indicating high severity for systems where it is present.
How do I fix CVE-2026-21930?
To fix CVE-2026-21930, you should apply the latest security updates provided by Oracle for the ZFS Storage Appliance Kit.
Who is affected by CVE-2026-21930?
CVE-2026-21930 affects users of Oracle ZFS Storage Appliance Kit version 8.8.
What type of vulnerability is CVE-2026-21930?
CVE-2026-21930 is a filesystem vulnerability that can be exploited by a high-privileged attacker.
Can CVE-2026-21930 be exploited remotely?
CVE-2026-21930 requires the attacker to have logon access to the infrastructure for exploitation.