Description
NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.
Published: 2026-08-05
Score: 5.4 Medium
EPSS: < 1% Very Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NetKids iMark, supplied by Integrated Systems Technologies, Inc., includes an Uncontrolled Search Path Element flaw (CWE‑427). An attacker who can authenticate to the application can leverage this weakness to execute arbitrary code with SYSTEM privileges. The primary impact is the ability to run code with full local system rights, compromising confidentiality, integrity, and availability of the affected host.

Affected Systems

The vulnerability affects Integrated Systems Technologies, Inc. NetKids iMark. No specific removed or fixed product versions are listed in the advisory; therefore all installations of NetKids iMark that have not been updated or patched are susceptible.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate risk profile. EPSS data is not available, so current exploit probability cannot be quantified, and the vulnerability is not registered in CISA KEV. The likely attack vector requires an authenticated session to the application; an attacker would need to obtain valid credentials or take advantage of an existing authenticated user to trigger the path‑tracing behavior that allows code execution.

Generated by OpenCVE AI on August 5, 2026 at 06:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update NetKids iMark to the latest version provided by Integrated Systems Technologies, Inc. that addresses the Uncontrolled Search Path Element flaw.
  • Limit authenticated access by enforcing strong, least‑privilege user credentials and monitoring for anomalous login activity.
  • Reconfigure the system’s PATH environment variable to exclude untrusted directories, ensuring only approved locations are searched during execution.

Generated by OpenCVE AI on August 5, 2026 at 06:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 14:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 05 Aug 2026 10:45:00 +0000

Type Values Removed Values Added
First Time appeared Integrated Systems Technologies, Inc.
Integrated Systems Technologies, Inc. netkids Imark
Vendors & Products Integrated Systems Technologies, Inc.
Integrated Systems Technologies, Inc. netkids Imark

Wed, 05 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Uncontrolled Search Path Element Allows Authenticated System‑Level Code Execution in NetKids iMark

Wed, 05 Aug 2026 05:30:00 +0000


Subscriptions

Integrated Systems Technologies, Inc. Netkids Imark
cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-05T13:33:27.938Z

Reserved: 2026-07-28T05:10:34.543Z

Link: CVE-2026-66344

cve-icon Vulnrichment

Updated: 2026-08-05T13:33:24.409Z

cve-icon NVD

Status : Received

Published: 2026-08-05T06:16:38.783

Modified: 2026-08-05T14:17:09.070

Link: CVE-2026-66344

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T10:18:37Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element