PatchSiren

PatchSiren cyber security CVE debrief

CVE-2026-8108 Fuji Electric CVE debrief

CVE-2026-8108 is a high-severity local privilege-related issue affecting Fuji Electric Tellus 5.0.2. According to the CISA CSAF advisory, installing Tellus adds a kernel driver that grants all users read and write permissions, which can undermine system integrity and confidentiality. The advisory was published on 2026-05-12 and does not appear in CISA KEV at this time.

Vendor
Fuji Electric
Product
Tellus
CVSS
HIGH 7.8
CISA KEV
Not listed in stored evidence
Original CVE published
2026-05-12
Original CVE updated
2026-05-12
Advisory published
2026-05-12
Advisory updated
2026-05-12

Who should care

Organizations running Fuji Electric Tellus 5.0.2, especially industrial control or operations teams that install or maintain the software on shared or production systems. Security teams responsible for local privilege hardening and software deployment controls should also review this advisory.

Technical summary

The supplied advisory describes a kernel driver installed by Fuji Tellus that grants all users read and write permissions. The published CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating a locally reachable issue requiring low privileges but with high impact if abused. CISA’s remediation notes specify that Fuji Electric recommends installing Tellus only with administrator privileges.

Defensive priority

High. The issue is locally exploitable, requires low privileges, and is rated HIGH with full confidentiality, integrity, and availability impact in the supplied scoring. Prioritize deployment restrictions and least-privilege controls on any affected systems.

Recommended defensive actions

  • Confirm whether Fuji Electric Tellus 5.0.2 is installed anywhere in your environment.
  • Restrict installation of Tellus to trusted administrative users only, as recommended in the advisory.
  • Review local privilege and file-permission controls on affected hosts to reduce the impact of over-permissive drivers.
  • If the product is required, place affected systems under enhanced monitoring for unexpected file or configuration changes.
  • Validate the advisory and vendor guidance before making changes in production OT/ICS environments.

Evidence notes

All substantive claims here are taken from the supplied CISA CSAF source item and its metadata: the product is Fuji Electric Tellus 5.0.2, the advisory describes a kernel driver granting all users read/write permissions, and the remediation says installation should be limited to administrator privileges. The published date used for timing context is 2026-05-12. No KEV entry is present in the supplied enrichment data.

Sources and references

Verified primary and authoritative sources

  • CVE-2026-8108 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2026-8108

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2026-8108 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8108

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-132-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.