Description
A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalation to root of an already authenticated user on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.
Published: 2026-07-22
Score: 8.5 High
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a local privilege escalation flaw that allows an already authenticated user to gain root access on systems running Fujitsu Linux openFT or Fujitsu Oracle Solaris openFT. It is a CWE-269 type weakness related to inappropriate use of privileged accounts. Successful exploitation would enable the actor to read or modify any file, install malicious software, or otherwise subvert the system’s security.

Affected Systems

This flaw affects Fujitsu Linux openFT and Fujitsu Oracle Solaris openFT versions before 12.1D00 on GNU/Linux and Oracle Solaris systems. End users running these older products are at risk.

Risk and Exploitability

The CVSS score of 8.5 indicates a high-severity local exploit. The EPSS score is < 1%, suggesting a very low but non-zero probability of exploitation in the wild. The vulnerability is not listed in the CISA KEV catalog. Because the flaw requires that the attacker already has local authentication, the likely attack vector is local and requires legitimate access to the system. Once authenticated, the attacker can elevate to root without additional steps.

Generated by OpenCVE AI on August 3, 2026 at 23:32 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Upgrade Fujitsu Linux openFT and Fujitsu Oracle Solaris openFT to version 12.1D00 or later.
  • If an immediate upgrade is not feasible, restrict privileged operations for authenticated users and enforce the principle of least privilege.
  • Continuously monitor logs for signs of unauthorized root activity and apply timely patches as releases become available.

Generated by OpenCVE AI on August 3, 2026 at 23:32 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 15:30:00 +0000

Type Values Removed Values Added
Description A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalation to root of an already authenticated user on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.
Title Authenticated local root privilege escalation vulnerability in openFT for Linux and Oracle Solaris
First Time appeared Fujitsu
Fujitsu linux Openft
Fujitsu oracle Solaris Openft
Weaknesses CWE-269
CPEs cpe:2.3:a:fujitsu:linux_openft:*:*:linux:*:*:*:*:*
cpe:2.3:a:fujitsu:linux_openft:12.1d00:*:linux:*:*:*:*:*
cpe:2.3:a:fujitsu:oracle_solaris_openft:*:*:oracle_solaris:*:*:*:*:*
cpe:2.3:a:fujitsu:oracle_solaris_openft:12.1d00:*:oracle_solaris:*:*:*:*:*
Vendors & Products Fujitsu
Fujitsu linux Openft
Fujitsu oracle Solaris Openft
References
Metrics cvssV3_1

{'score': 7.8, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 8.5, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Fujitsu Linux Openft Oracle Solaris Openft
cve-icon MITRE

Status: PUBLISHED

Assigner: FTI

Published:

Updated: 2026-07-22T18:51:08.134Z

Reserved: 2026-07-22T14:31:14.251Z

Link: CVE-2026-16607

cve-icon Vulnrichment

Updated: 2026-07-22T18:51:03.698Z

cve-icon NVD

Status : Deferred

Published: 2026-07-22T16:17:16.963

Modified: 2026-07-22T20:52:35.747

Link: CVE-2026-16607

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:45:05Z

Weaknesses
  • CWE-269

    Improper Privilege Management