CVE-2026-66109
Received
Received - Intake
Arbitrary Code Execution in SKYSEA Client View and SKYMEC IT Manager
Vulnerability report for CVE-2026-66109, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.
Publication date: 2026-08-25
Last updated on: 2026-08-25
Assigner: JPCERT/CC
Description
Description
A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to the Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| sky_co_ltd | skysea_client_view | to 21.210.01f (inc) |
| sky_co_ltd | skymec_it_manager | From 2023.225.03a (inc) to 2024.005.10a (inc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-862 | The product does not perform an authorization check when an actor attempts to access a resource or perform an action. |