Junglewise Threat Intelligence

CVE-2026-56437: Fuji Electric Pupsman uncontrolled search path in installer

CVE-2026-56437 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Fuji Electric Pupsman is software used to manage Uninterruptible Power Supply (UPS) systems, ensuring servers shut down safely during power outages. A security flaw in the software's installer could allow an attacker to gain full control over a computer if a user is tricked into running the installer from a folder containing a malicious file. This could lead to a complete system takeover, unauthorized data access, or disruption of power management operations.

Technical details

An uncontrolled search path element vulnerability (CWE-427) exists in the installer for Fuji Electric Pupsman versions prior to 3.9.0. The vulnerability occurs because the installer attempts to load DLL dependencies from its current working directory without sufficient validation. A local attacker can exploit this by placing a maliciously crafted DLL file in the same directory as the installer executable. When a user executes the installer (requiring user interaction), the malicious DLL is loaded and executed with SYSTEM privileges. This allows for full local privilege escalation. The issue is resolved in Pupsman version 3.9.0.

Affected products

  • Fuji Electric Co.,Ltd. Pupsman prior to 3.9.0

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory
  • 2026-07-08: patched: Fixed in version 3.9.0

References

Related threats