CVE-2026-16607

Fujitsu · Linux openFT and Oracle Solaris openFT

A privilege escalation vulnerability in Fujitsu Linux openFT and Oracle Solaris openFT allows local authenticated attackers to gain unauthorized privileges due to improper privilege management.

Executive summary

A high-severity privilege escalation vulnerability in Fujitsu openFT software allows local attackers to gain elevated system access.

Vulnerability

This is a privilege management flaw (CWE-269) where insufficient restrictions on process operations allow a local authenticated attacker to escalate their privileges within the host operating system.

Business impact

The ability for a local user to escalate privileges poses a significant risk to the confidentiality, integrity, and availability of the host system. Successful exploitation could grant an attacker administrative control, potentially leading to unauthorized data access, system configuration changes, or total service compromise. The CVSS score of 7.8 reflects the high impact on the local environment despite the requirement for local access.

Remediation

Immediate Action: Update Fujitsu Linux openFT and Oracle Solaris openFT to version 12.1D00 or later to apply the necessary security fixes.

Proactive Monitoring: Audit system logs for unusual process execution or attempts to access restricted administrative functions by non-privileged accounts.

Compensating Controls: Restrict local shell access to the affected systems, ensuring that only authorized personnel can execute commands on the host.

Exploitation status

Public Exploit Available: No

Analyst recommendation

Given the severity of potential privilege escalation, administrators should prioritize patching these instances during the next maintenance window. Upgrading to version 12.1D00 is the only reliable method to eliminate this vulnerability.