Junglewise Threat Intelligence

CVE-2026-8108: Fuji Electric Tellus privilege escalation in kernel driver

CVE-2026-8108 · Severity: high · CVSS 7.8 · Published 2026-05-12

Executive brief

Fuji Electric Tellus, a software tool used in industrial manufacturing environments, installs a kernel driver that incorrectly grants read and write permissions to all users on the system. A local attacker with basic user access could exploit this to gain full administrative control (System privileges). This could lead to the theft of sensitive operational data, the deletion of critical files, or a disruption of industrial processes.

Technical details

The vulnerability is classified as an Exposed Dangerous Method or Function (CWE-749) within a kernel driver installed by Fuji Electric Tellus version 5.0.2.0. During installation, the driver is configured with overly permissive Access Control Lists (ACLs) that grant global read/write access to all users. A local, authenticated attacker can interact with this driver to escalate privileges to SYSTEM. Successful exploitation allows for arbitrary file manipulation (opening or deleting files) and can lead to a total loss of confidentiality, integrity, and availability on the affected host. The vendor recommends ensuring the software is installed only with administrator privileges as a mitigation step.

Affected products

  • Fuji Electric Tellus 5.0.2.0

Timeline

  • 2026-05-12: advisory: Initial publication by CISA (ICSA-26-132-01)
  • 2026-05-12: disclosed

References