Description
Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwritten in the system directory or backup directory by a non-administrative user.
Published: 2026-03-09
Score: 6.8 Medium
EPSS: < 1% Very Low
KEV: No
Impact: Local privilege escalation via non‑administrative write to system directories
Action: Apply Patch
AI Analysis

Impact

Digital Arts i-フィルター products have been configured with incorrect default permissions on sensitive files within system and backup directories. As a consequence, a regular user lacking administrative privileges can create or overwrite files in these directories, which may allow the deployment of malicious code or the modification of critical files. The flaw could lead to local privilege escalation or persistence on the affected machines.

Affected Systems

The vulnerability affects multiple products from Digital Arts Inc., including Digital Arts@Cloud Agent for Windows, i-FILTER ブラウザー&クラウド MultiAgent for Windows, i-フィルター 10, i-フィルター 6.0, i-フィルター for ZAQ, i-フィルター for ネットカフェ, i-フィルター for プロバイダー, and i-フィルター for マルチデバイス, as well as Fujitsu Limited’s i-FILTER Browser & Cloud MultiAgent for Windows, Inventit Inc.’s MobiConnect i-FILTER Browser Option MultiAgent for Windows, and OPTiM Corporation’s Optimal Biz Web Filtering Powered by i-FILTER. The CVE does not list specific version ranges, so any released version of these products is potentially affected.

Risk and Exploitability

The CVSS score of 6.8 indicates moderate severity, while the EPSS score of less than 1% shows that exploitation is considered unlikely under current threat data. The flaw is not listed in the CISA KEV catalog, which means there are no publicly confirmed leveraged exploits. An attacker would need local access to a machine running one of the affected products and would exploit the improper file permissions to write malicious binaries or scripts to a system or backup directory, a step that does not require administrative credentials. Once placed, such files could be executed to gain elevated privileges or establish persistence. The overall risk is moderate, but the impact remains significant for environments where these directories contain exploitable binaries or configuration files.

Generated by OpenCVE AI on April 16, 2026 at 10:03 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Download and install the vendor‑supplied security patch or the latest release for all affected Digital Arts i‑フィルター products.
  • Re‑apply correct file permissions on the system and backup directories to deny write access to non‑administrative users, ensuring only privileged accounts can create or modify files there.
  • Regularly audit the system and backup directories for unexpected file creations or modifications and review event logs for write attempts by non‑privileged accounts.

Generated by OpenCVE AI on April 16, 2026 at 10:03 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 16 Apr 2026 10:30:00 +0000

Type Values Removed Values Added
Title Improper File Access Permissions Allow Non‑Administrative Write to System Directories

Tue, 10 Mar 2026 15:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 10 Mar 2026 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Digital Arts
Digital Arts digitalarts@cloud Agent (for Windows)
Digital Arts i-filter ブラウザー&クラウド Multiagent For Windows
Digital Arts i-フィルター 10 (windows Version Only)
Digital Arts i-フィルター 6.0
Digital Arts i-フィルター For Zaq (windows Version Only)
Digital Arts i-フィルター For ネットカフェ
Digital Arts i-フィルター For プロバイダー
Digital Arts i-フィルター For マルチデバイス (windows Version Only)
Fujitsu
Fujitsu i-filter Browser & Cloud Multiagent For Windows
Inventit
Inventit mobiconnect I-filter Browser Option Multiagent For Windows
Optim Corporation
Optim Corporation optimal Biz Web Filtering Powered By I-filter (windows Version)
Vendors & Products Digital Arts
Digital Arts digitalarts@cloud Agent (for Windows)
Digital Arts i-filter ブラウザー&クラウド Multiagent For Windows
Digital Arts i-フィルター 10 (windows Version Only)
Digital Arts i-フィルター 6.0
Digital Arts i-フィルター For Zaq (windows Version Only)
Digital Arts i-フィルター For ネットカフェ
Digital Arts i-フィルター For プロバイダー
Digital Arts i-フィルター For マルチデバイス (windows Version Only)
Fujitsu
Fujitsu i-filter Browser & Cloud Multiagent For Windows
Inventit
Inventit mobiconnect I-filter Browser Option Multiagent For Windows
Optim Corporation
Optim Corporation optimal Biz Web Filtering Powered By I-filter (windows Version)

Mon, 09 Mar 2026 22:45:00 +0000

Type Values Removed Values Added
Description Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwritten in the system directory or backup directory by a non-administrative user.
Weaknesses CWE-276
References
Metrics cvssV3_0

{'score': 5.5, 'vector': 'CVSS:3.0/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:N'}

cvssV4_0

{'score': 6.8, 'vector': 'CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N'}


Subscriptions

Digital Arts Digitalarts@cloud Agent (for Windows) I-filter ブラウザー&クラウド Multiagent For Windows I-フィルター 10 (windows Version Only) I-フィルター 6.0 I-フィルター For Zaq (windows Version Only) I-フィルター For ネットカフェ I-フィルター For プロバイダー I-フィルター For マルチデバイス (windows Version Only)
Fujitsu I-filter Browser & Cloud Multiagent For Windows
Inventit Mobiconnect I-filter Browser Option Multiagent For Windows
Optim Corporation Optimal Biz Web Filtering Powered By I-filter (windows Version)
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-03-10T14:16:29.163Z

Reserved: 2026-02-26T00:21:16.561Z

Link: CVE-2026-28267

cve-icon Vulnrichment

Updated: 2026-03-10T14:16:25.685Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-03-10T17:38:38.227

Modified: 2026-03-11T13:53:47.157

Link: CVE-2026-28267

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-04-16T10:15:26Z

Weaknesses