CVE-2026-28267
Deferred
Deferred - Pending Action
Improper File Permission Allows Unauthorized File Overwrite in i
Publication date: 2026-03-10
Last updated on: 2026-05-19
Assigner: JPCERT/CC
Description
Description
Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwritten in the system directory or backup directory by a non-administrative user.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| digital_arts_inc | i-フィルター | to 10.02.00 (exc) |
| digital_arts_inc | i-フィルター | to 6.00.57 (exc) |
| digital_arts_inc | i-フィルター | to 6.10.57 (exc) |
| digital_arts_inc | i-フィルター | to 2.00.30 (exc) |
| digital_arts_inc | i-filter_ブラウザー&クラウド_multiagent | to 4.93R13 (exc) |
| digital_arts_inc | digitalarts@cloud_agent | to 1.70R01 (exc) |
| optim_corporation | related_product | to 4.93R13 (exc) |
| inventit_inc | related_product | to 4.93R13 (exc) |
| fujitsu_limited | related_product | to 4.93R13 (exc) |
| digital_arts | i-フィルター | to 6.00.57 (exc) |
| digital_arts | i-フィルター | to 10.02.00 (exc) |
| digital_arts | i-フィルター | to 6.10.57 (exc) |
| digital_arts | i-フィルター | to 2.00.30 (exc) |
| digital_arts | i-filter_ブラウザー&クラウド_multiagent | to 4.93R13 (exc) |
| digital_arts | digitalarts@cloud_agent | to 1.70R01 (exc) |
| optim | optim | to 4.93R13 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-276 | During installation, installed file permissions are set to allow anyone to modify those files. |