Description
The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges.
Published: 2026-02-27
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Arbitrary code execution with SYSTEM privileges
Action: Immediate Patch
AI Analysis

Impact

Installers for Soliton SecureBrowser II, SecureBrowser for OneGate, and SecureWorkspace contain incorrect default permissions that can be leveraged by an attacker to execute arbitrary code with SYSTEM privileges. The weakness corresponds to CWE‑276 (Incorrect Permission Assignment) and CWE‑863 (Insufficient or Incorrect Permission Enforcement). As a result, a malicious actor could gain full control of the affected Windows machine if they can run a malicious component during or after installation.

Affected Systems

The vulnerability affects Soliton Systems K.K. products: SecureBrowser II, SecureBrowser for OneGate, and SecureWorkspace (formerly WrappingBox). All products available on Windows platforms are susceptible; specific versions are not enumerated in the advisory, so any installation build should be considered vulnerable until a patch is applied.

Risk and Exploitability

The CVSS score of 5.4 indicates moderate severity, and the EPSS score of less than 1% suggests that exploitation is unlikely but not impossible. The vulnerability is not listed in the CISA KEV catalog, so it is not known to have been actively exploited in the wild. The attack vector is inferred to be the installation process; an attacker who can influence the installer—directly or via a compromised installation medium—could trigger the misconfigured permissions and achieve privilege escalation.

Generated by OpenCVE AI on April 17, 2026 at 14:02 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the latest Soliton SecureBrowser II installer from the vendor’s support site
  • Uninstall any existing installation of SecureBrowser II, SecureBrowser for OneGate, or SecureWorkspace and then reinstall using the updated installer to ensure correct permissions
  • Audit the file permissions and access levels after installation to confirm that they have been set as intended

Generated by OpenCVE AI on April 17, 2026 at 14:02 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 17 Mar 2026 16:00:00 +0000

Type Values Removed Values Added
First Time appeared Soliton
Soliton securebrowser For Onegate
Soliton securebrowser Ii
Soliton secureworkspace
Weaknesses CWE-863
CPEs cpe:2.3:a:soliton:securebrowser_for_onegate:1.0.0:*:*:*:*:windows:*:*
cpe:2.3:a:soliton:securebrowser_ii:*:*:*:*:*:windows:*:*
cpe:2.3:a:soliton:secureworkspace:*:*:*:*:*:*:*:*
Vendors & Products Soliton
Soliton securebrowser For Onegate
Soliton securebrowser Ii
Soliton secureworkspace
Metrics cvssV3_1

{'score': 6.7, 'vector': 'CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}


Fri, 27 Feb 2026 19:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Fri, 27 Feb 2026 16:15:00 +0000

Type Values Removed Values Added
First Time appeared Soliton Systems K.k.
Soliton Systems K.k. soliton Securebrowser For Onegate
Soliton Systems K.k. soliton Securebrowser Ii
Soliton Systems K.k. soliton Secureworkspace (formerly Wrappingbox)
Vendors & Products Soliton Systems K.k.
Soliton Systems K.k. soliton Securebrowser For Onegate
Soliton Systems K.k. soliton Securebrowser Ii
Soliton Systems K.k. soliton Secureworkspace (formerly Wrappingbox)

Fri, 27 Feb 2026 06:00:00 +0000

Type Values Removed Values Added
Description The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges.
Weaknesses CWE-276
References
Metrics cvssV3_0

{'score': 6.7, 'vector': 'CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.4, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Subscriptions

Soliton Securebrowser For Onegate Securebrowser Ii Secureworkspace
Soliton Systems K.k. Soliton Securebrowser For Onegate Soliton Securebrowser Ii Soliton Secureworkspace (formerly Wrappingbox)
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-02-27T18:52:30.918Z

Reserved: 2026-02-25T04:39:12.761Z

Link: CVE-2026-27653

cve-icon Vulnrichment

Updated: 2026-02-27T18:52:25.765Z

cve-icon NVD

Status : Analyzed

Published: 2026-02-27T06:17:59.753

Modified: 2026-03-17T15:48:27.283

Link: CVE-2026-27653

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-17T14:15:21Z

Weaknesses