PatchSiren cyber security CVE debrief
CVE-2026-8108 Fuji Electric CVE debrief
CVE-2026-8108 is a high-severity local privilege-related issue affecting Fuji Electric Tellus 5.0.2. According to the CISA CSAF advisory, installing Tellus adds a kernel driver that grants all users read and write permissions, which can undermine system integrity and confidentiality. The advisory was published on 2026-05-12 and does not appear in CISA KEV at this time.
- Vendor
- Fuji Electric
- Product
- Tellus
- CVSS
- HIGH 7.8
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2026-05-12
- Original CVE updated
- 2026-05-12
- Advisory published
- 2026-05-12
- Advisory updated
- 2026-05-12
Who should care
Organizations running Fuji Electric Tellus 5.0.2, especially industrial control or operations teams that install or maintain the software on shared or production systems. Security teams responsible for local privilege hardening and software deployment controls should also review this advisory.
Technical summary
The supplied advisory describes a kernel driver installed by Fuji Tellus that grants all users read and write permissions. The published CVSS vector is CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H, indicating a locally reachable issue requiring low privileges but with high impact if abused. CISA’s remediation notes specify that Fuji Electric recommends installing Tellus only with administrator privileges.
Defensive priority
High. The issue is locally exploitable, requires low privileges, and is rated HIGH with full confidentiality, integrity, and availability impact in the supplied scoring. Prioritize deployment restrictions and least-privilege controls on any affected systems.
Recommended defensive actions
- Confirm whether Fuji Electric Tellus 5.0.2 is installed anywhere in your environment.
- Restrict installation of Tellus to trusted administrative users only, as recommended in the advisory.
- Review local privilege and file-permission controls on affected hosts to reduce the impact of over-permissive drivers.
- If the product is required, place affected systems under enhanced monitoring for unexpected file or configuration changes.
- Validate the advisory and vendor guidance before making changes in production OT/ICS environments.
Evidence notes
All substantive claims here are taken from the supplied CISA CSAF source item and its metadata: the product is Fuji Electric Tellus 5.0.2, the advisory describes a kernel driver granting all users read/write permissions, and the remediation says installation should be limited to administrator privileges. The published date used for timing context is 2026-05-12. No KEV entry is present in the supplied enrichment data.
Sources and references
Verified primary and authoritative sources
-
CVE-2026-8108 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2026-8108
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2026-8108 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2026-8108
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-132-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-132-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-alerts/ics-alert-10-301-01
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.