CVE-2026-16607
Received Received - Intake

Local Privilege Escalation in Fujitsu Software openFT

Vulnerability report for CVE-2026-16607, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: 763b0cbd-1a52-41de-b280-f255286be201

Description

A vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00 allows for local privilege escalation to root of an already authenticated user on GNU/Linux or Oracle Solaris. The Fsas Technologies PSIRT obtained that intelligence internally and covers the CVE beyond its CNA scope under existing agreement with Fujitsu Germany.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
fujitsu software_linux_openft to 12.1D00 (exc)
fujitsu software_oracle_solaris_openft to 12.1D00 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-269 The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is a local privilege escalation vulnerability in Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT before version 12.1D00. It allows an already authenticated user to escalate privileges to root on affected systems running GNU/Linux or Oracle Solaris.

Detection Guidance

The provided CVE data does not include specific detection commands or methods for identifying this vulnerability on a system. Users should check Fujitsu's official security advisories or contact Fsas Technologies for guidance on detection methods.

Impact Analysis

If you use affected versions of Fujitsu Software Linux openFT or Oracle Solaris openFT, an attacker with local access could exploit this to gain full control of your system, potentially accessing sensitive data or installing malware.

Compliance Impact

The vulnerability allows local privilege escalation to root for authenticated users, which could lead to unauthorized access to sensitive data or system control. This may violate compliance requirements under GDPR (data protection) and HIPAA (healthcare data security) by enabling unauthorized data access or modification. Affected organizations must assess their exposure and apply patches promptly to maintain compliance.

Mitigation Strategies

Update Fujitsu Software Linux openFT and Fujitsu Software Oracle Solaris openFT to version 12.1D00 or later to address the local privilege escalation vulnerability.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16607. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart