JVN#33423625
Multiple vulnerabilities in SKYSEA Client View and SKYMEC IT Manager
Overview
SKYSEA Client View and SKYMEC IT Manager provided by Sky Co., LTD. contains multiple vulnerabilities.
Products Affected
CVE-2026-66109, CVE-2026-68960
- SKYSEA Client View Ver.21.210.01f and earlier
- SKYMEC IT Manager Ver.2023.225.03a and Ver.2024.005.10a
- SKYSEA Client View Ver.19.300.09h to Ver.21.210.01f
- SKYMEC IT Manager Ver.2024.005.10a
- SKYSEA Client View Ver.21.300.12g and earlier
- SKYMEC IT Manager Ver.2025.205.08a and earlier
Description
SKYSEA Client View and SKYMEC IT Manager provided by Sky Co., LTD. contains multiple vulnerabilities listed below.
- Missing authorization (CWE-862)
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.5
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 7.8
- CVE-2026-66109
- Path traversal (CWE-22)
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H Base Score 5.8
- CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Base Score 8.5
- CVE-2026-68062
- This vulnerability is due to an incomplete fix for CVE-2024-41726, as mentioned in JVN#84326763.
- Path traversal (CWE-25)
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H Base Score 5.8
- CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Base Score 8.5
- CVE-2026-68959
- This vulnerability is due to an incomplete fix for CVE-2024-41726, as mentioned in JVN#84326763.
- Stack-based buffer overflow (CWE-121)
- CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H Base Score 5.8
- CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H Base Score 8.5
- CVE-2026-68960
- Incorrect default permissions (CWE-276)
- CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N Base Score 8.5
- CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H Base Score 7.8
- CVE-2026-69665
Impact
- An attacker who can log in to the Windows system on which the affected products is installed may execute arbitrary code with
SYSTEMprivilege (CVE-2026-66109, CVE-2026-69665). - An attacker who can log in to a Windows system on which the affected products is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system (CVE-2026-68062, CVE-2026-68959, CVE-2026-68960).
Solution
Apply the patch
Apply the patch provided by the developer.
Vendor Status
JPCERT/CC Addendum
Vulnerability Analysis by JPCERT/CC
Credit
CVE-2026-66109, CVE-2026-68062, CVE-2026-68959, CVE-2026-68960
Ruslan Sayfiev and Denis Faiustov of Fujitsu Limitedreported these vulnerabilities to Sky Co., LTD. and coordinated. Sky Co., LTD. and JPCERT/CC published respective advisories in order to notify users of the solutions through JVN.
CVE-2026-69665
Yuji Hayamizu reported this vulnerability to Sky Co., LTD. and coordinated. Sky Co., LTD. and JPCERT/CC published respective advisories in order to notify users of this vulnerability.
Other Information
| JPCERT Alert |
|
| JPCERT Reports |
|
| CERT Advisory |
|
| CPNI Advisory |
|
| TRnotes |
|
| CVE |
CVE-2026-66109 |
|
CVE-2026-68062 |
|
|
CVE-2026-68959 |
|
|
CVE-2026-68960 |
|
|
CVE-2026-69665 |
|
| JVN iPedia |
JVNDB-2026-000097 |
Update History
- 2026/08/24
- Information under the section [Products Affected] was updated