CVE-2026-27653
Received
Received - Intake
Incorrect Default Permissions in Soliton Installers Allow SYSTEM Code Execution
Publication date: 2026-02-27
Last updated on: 2026-03-17
Assigner: JPCERT/CC
Description
Description
The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| soliton | securebrowser_for_onegate | 1.0.0 |
| soliton | securebrowser_ii | From 2.0.0 (inc) to 2.0.15 (exc) |
| soliton | secureworkspace | From 1.0.0 (inc) to 1.4.8 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-863 | The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. |
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |