CVE-2026-68959

Summary

SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an incomplete fix for CVE-2024-41726.

Affected Software

VendorProductVersion RangeStatus
Sky Co., LTD.SKYSEA Client ViewVer.19.300.09h <= Ver.21.210.01faffected
Sky Co., LTD.SKYMEC IT ManagerVer.2024.005.10aaffected

Weaknesses

  • CWE-25: Path Traversal: '/../filedir'

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References