Local Privilege Escalation in Fuji Electric Tellus pcid64 Driver (CVE‑2026‑8108) Threatens Industrial Control Systems
What It Is — A vulnerability in the pcid64 driver of Fuji Electric’s Tellus platform allows a local attacker who can run low‑privileged code to execute arbitrary code as SYSTEM. The flaw stems from exposed dangerous methods that can be invoked to elevate privileges.
Exploitability — CVSS 7.8 (AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H). No public exploit code is known, but the low attack complexity and high impact make it a prime target for threat actors with limited foothold on an OT host.
Affected Products — Fuji Electric Tellus (industrial control system) – all versions prior to the vendor‑released patch.
Why It Matters for Compliance & Audit Readiness
- SOC 2 CC6.1 – System Operations requires documented evidence that privileged‑access mechanisms are protected; a privilege‑escalation flaw indicates a control gap.
- Continuous control monitoring must capture patch‑management status for OT assets; missing patches become audit findings.
- Demonstrating timely remediation and evidence of remediation actions strengthens the Trust Center proof you can present to customers and auditors.
Recommended Actions
- Deploy Fuji Electric’s security update immediately on all Tellus installations.
- Map the vulnerability to the SOC 2 CC6.1 control and record remediation evidence in your continuous‑compliance platform.
- Enable automated patch‑status monitoring for OT devices to provide real‑time audit evidence.
- Review and tighten local execution policies to limit the ability of low‑privileged code to invoke driver methods.
Source: Zero Day Initiative advisory ZDI‑26‑439 (CVE‑2026‑8108)