Junglewise Threat Intelligence

CVE-2026-57895: Fuji Electric Pupsman incorrect default permissions in installation folder

CVE-2026-57895 · Severity: high · CVSS 7.8 · Published 2026-07-08

Executive brief

Fuji Electric Pupsman, a software suite used to manage Uninterruptible Power Supplies (UPS) and automate server shutdowns during power failures, contains a security flaw in its folder permissions. A local user on the system could replace legitimate files with malicious ones, allowing them to take full control of the computer with administrative privileges. This could lead to a complete system takeover, data theft, or disruption of power management operations.

Technical details

An incorrect default permissions vulnerability (CWE-276) exists in Fuji Electric Pupsman versions prior to 3.9.0. The software's installation folder is configured with insecure access control lists (ACLs), allowing low-privileged local users to write files into the directory. An attacker can exploit this by placing a malicious executable or DLL in the installation folder. Because the application or its associated services run with elevated privileges, this results in arbitrary code execution with SYSTEM authority. The issue is resolved in version 3.9.0.

Affected products

  • Fuji Electric Co.,Ltd. Pupsman prior to 3.9.0

Timeline

  • 2026-07-08: disclosed
  • 2026-07-08: advisory
  • 2026-07-08: patched: Fixed in version 3.9.0

References

Related threats