Junglewise Threat Intelligence

CVE-2026-16607: Fujitsu openFT local privilege escalation to root

CVE-2026-16607 · Severity: high · CVSS 7.8 · Published 2026-07-22

Executive brief

A vulnerability in Fujitsu openFT, a managed file transfer solution, allows a user who already has basic access to a Linux or Solaris system to gain full administrative (root) control. This could allow an attacker to bypass security restrictions, access sensitive files, or disrupt business-critical file transfer operations. Organizations using affected versions should update to version 12.1D00 to prevent unauthorized system takeovers.

Technical details

A privilege management vulnerability (CWE-269) exists in Fujitsu Software openFT for Linux and Oracle Solaris. The flaw allows a local, authenticated user with low privileges to escalate their permissions to root. The vulnerability affects Linux openFT versions prior to 12.1D00 (specifically up to 12.1C96) and Oracle Solaris openFT versions prior to 12.1D00 (specifically up to 12.1C95). Attackers can exploit this to gain full control over the underlying operating system. The issue is resolved in version 12.1D00.

Affected products

  • Fujitsu Linux openFT before 12.1D00
  • Fujitsu Oracle Solaris openFT before 12.1D00

Timeline

  • 2026-07-20: advisory: Initial security notice published by Fsas Technologies PSIRT
  • 2026-07-22: disclosed: CVE published to NVD

References

Related threats