You are using an out of date browser. It may not display this or other websites correctly. You should upgrade or use an alternative browser.
cve-2026-8108
About this tag
CVE-2026-8108 is a privilege escalation vulnerability in Fuji Electric Tellus 5.0.2, a Windows-based HMI and monitoring software used in industrial control systems. The flaw resides in a kernel driver installed by Tellus that grants overly permissive access, allowing a local user to elevate privileges to SYSTEM on affected Windows machines. Published in a CISA advisory on May 12, 2026, this vulnerability is not remotely exploitable but poses a significant risk in environments where workstations are not tightly controlled. For plant operators, integrators, and engineering teams, CVE-2026-8108 underscores the importance of treating industrial Windows systems with the same endpoint discipline as enterprise IT, especially when kernel-level software is involved.
CISA published an industrial control systems advisory on May 12, 2026, warning that Fuji Electric Tellus 5.0.2 installs a kernel driver with permissions that can let a local user elevate privileges to system on affected Windows machines. The flaw, tracked as CVE-2026-8108, is not a...