Published:2026/08/24  Last Updated:2026/08/24

JVN#33423625
Multiple vulnerabilities in SKYSEA Client View and SKYMEC IT Manager

Overview

SKYSEA Client View and SKYMEC IT Manager provided by Sky Co., LTD. contains multiple vulnerabilities.

Products Affected

CVE-2026-66109, CVE-2026-68960

  • SKYSEA Client View Ver.21.210.01f and earlier
  • SKYMEC IT Manager Ver.2023.225.03a and Ver.2024.005.10a
CVE-2026-68062, CVE-2026-68959
  • SKYSEA Client View Ver.19.300.09h to Ver.21.210.01f
  • SKYMEC IT Manager Ver.2024.005.10a
CVE-2026-69665
  • SKYSEA Client View Ver.21.300.12g and earlier
  • SKYMEC IT Manager Ver.2025.205.08a and earlier

Description

SKYSEA Client View and SKYMEC IT Manager provided by Sky Co., LTD. contains multiple vulnerabilities listed below.

  • Missing authorization (CWE-862)
    • CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.5
    • CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 7.8
    • CVE-2026-66109
  • Path traversal (CWE-22)
    • CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H Base Score 5.8
    • CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Base Score 8.5
    • CVE-2026-68062
    • This vulnerability is due to an incomplete fix for CVE-2024-41726, as mentioned in JVN#84326763.
  • Path traversal (CWE-25)
    • CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H Base Score 5.8
    • CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Base Score 8.5
    • CVE-2026-68959
    • This vulnerability is due to an incomplete fix for CVE-2024-41726, as mentioned in JVN#84326763.
  • Stack-based buffer overflow (CWE-121)
    • CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H Base Score 5.8
    • CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Base Score 8.5
    • CVE-2026-68960
  • Incorrect default permissions (CWE-276)
    • CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.5
    • CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 7.8
    • CVE-2026-69665

Impact

  • An attacker who can log in to the Windows system on which the affected products is installed may execute arbitrary code with SYSTEM privilege (CVE-2026-66109, CVE-2026-69665).
  • An attacker who can log in to a Windows system on which the affected products is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system (CVE-2026-68062, CVE-2026-68959, CVE-2026-68960).

Solution

Apply the patch
Apply the patch provided by the developer.

References

  1. Japan Vulnerability Notes JVN#84326763
    Multiple vulnerabilities in SKYSEA Client View

JPCERT/CC Addendum

Vulnerability Analysis by JPCERT/CC

Credit

CVE-2026-66109, CVE-2026-68062, CVE-2026-68959, CVE-2026-68960
Ruslan Sayfiev and Denis Faiustov of Fujitsu Limitedreported these vulnerabilities to Sky Co., LTD. and coordinated. Sky Co., LTD. and JPCERT/CC published respective advisories in order to notify users of the solutions through JVN.

CVE-2026-69665
Yuji Hayamizu reported this vulnerability to Sky Co., LTD. and coordinated. Sky Co., LTD. and JPCERT/CC published respective advisories in order to notify users of this vulnerability.

Other Information

JPCERT Alert
JPCERT Reports
CERT Advisory
CPNI Advisory
TRnotes
CVE CVE-2026-66109
CVE-2026-68062
CVE-2026-68959
CVE-2026-68960
CVE-2026-69665
JVN iPedia JVNDB-2026-000097

Update History

2026/08/24
Information under the section [Products Affected] was updated