CVE-2026-16607
Fujitsu · Linux openFT and Oracle Solaris openFT
A privilege escalation vulnerability in Fujitsu Linux openFT and Oracle Solaris openFT allows local authenticated attackers to gain unauthorized privileges due to improper privilege management.
Executive summary
A high-severity privilege escalation vulnerability in Fujitsu openFT software allows local attackers to gain elevated system access.
Vulnerability
This is a privilege management flaw (CWE-269) where insufficient restrictions on process operations allow a local authenticated attacker to escalate their privileges within the host operating system.
Business impact
The ability for a local user to escalate privileges poses a significant risk to the confidentiality, integrity, and availability of the host system. Successful exploitation could grant an attacker administrative control, potentially leading to unauthorized data access, system configuration changes, or total service compromise. The CVSS score of 7.8 reflects the high impact on the local environment despite the requirement for local access.
Remediation
Immediate Action: Update Fujitsu Linux openFT and Oracle Solaris openFT to version 12.1D00 or later to apply the necessary security fixes.
Proactive Monitoring: Audit system logs for unusual process execution or attempts to access restricted administrative functions by non-privileged accounts.
Compensating Controls: Restrict local shell access to the affected systems, ensuring that only authorized personnel can execute commands on the host.
Exploitation status
Public Exploit Available: No
Analyst recommendation
Given the severity of potential privilege escalation, administrators should prioritize patching these instances during the next maintenance window. Upgrading to version 12.1D00 is the only reliable method to eliminate this vulnerability.