CVE-2026-69665
Deferred Deferred - Pending Action

Incorrect Default Permissions in SKYSEA Client View and SKYMEC IT Manager Allow Privilege Escalation

Vulnerability report for CVE-2026-69665, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-25

Last updated on: 2026-08-28

Assigner: JPCERT/CC

Description

SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-25
Last Modified
2026-08-28
Generated
2026-09-14
AI Q&A
2026-08-25
EPSS Evaluated
2026-09-13
NVD
EUVD

Affected Vendors & Products

Showing 2 associated CPEs
Vendor Product Version / Range
sky_co_ltd skysea_client_view to 21.210.01f (inc)
sky_co_ltd skymec_it_manager From 2023.225.03a (inc) to 2024.005.10a (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-276 During installation, installed file permissions are set to allow anyone to modify those files.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

SKYSEA Client View and SKYMEC IT Manager have incorrect default permissions. An attacker who can log into a Windows system with the affected product installed may execute arbitrary code with SYSTEM privilege.

Detection Guidance

This vulnerability is due to incorrect default permissions in SKYSEA Client View and SKYMEC IT Manager. Detection involves checking installed versions of these products against affected versions (SKYSEA Client View Ver.21.210.01f or earlier, SKYMEC IT Manager Ver.2023.225.03a or 2024.005.10a). Use system commands to list installed software versions.

Impact Analysis

An attacker could gain full control over the affected system, install malware, steal data, or disrupt operations. The high CVSS scores indicate significant risk of confidentiality, integrity, and availability compromise.

Compliance Impact

This vulnerability could lead to unauthorized access to sensitive data, violating GDPR and HIPAA requirements for data protection and access controls.

Mitigation Strategies

Apply the latest security patches or updates from the vendor for SKYSEA Client View and SKYMEC IT Manager to fix incorrect default permissions. Restrict user access to systems where these products are installed and monitor for unauthorized SYSTEM privilege escalation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-69665. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart