Description
NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.
Published: 2026-08-05
Score: 5.4 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

NetKids iMark, supplied by Integrated Systems Technologies, Inc., includes an Uncontrolled Search Path Element flaw (CWE‑427). An attacker who can authenticate to the application can leverage this weakness to execute arbitrary code with SYSTEM privileges. The primary impact is the ability to run code with full local system rights, compromising confidentiality, integrity, and availability of the affected host.

Affected Systems

The vulnerability affects Integrated Systems Technologies, Inc. NetKids iMark. No specific removed or fixed product versions are listed in the advisory; therefore all installations of NetKids iMark that have not been updated or patched are susceptible.

Risk and Exploitability

The CVSS score of 5.4 indicates a moderate risk profile. EPSS data is not available, so current exploit probability cannot be quantified, and the vulnerability is not registered in CISA KEV. The likely attack vector requires an authenticated session to the application; an attacker would need to obtain valid credentials or take advantage of an existing authenticated user to trigger the path‑tracing behavior that allows code execution.

Generated by OpenCVE AI on August 5, 2026 at 06:54 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Update NetKids iMark to the latest version provided by Integrated Systems Technologies, Inc. that addresses the Uncontrolled Search Path Element flaw.
  • Limit authenticated access by enforcing strong, least‑privilege user credentials and monitoring for anomalous login activity.
  • Reconfigure the system’s PATH environment variable to exclude untrusted directories, ensuring only approved locations are searched during execution.

Generated by OpenCVE AI on August 5, 2026 at 06:54 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Wed, 05 Aug 2026 07:15:00 +0000

Type Values Removed Values Added
Title Uncontrolled Search Path Element Allows Authenticated System‑Level Code Execution in NetKids iMark

Wed, 05 Aug 2026 05:30:00 +0000


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-05T04:25:58.310Z

Reserved: 2026-07-28T05:10:34.543Z

Link: CVE-2026-66344

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-05T07:00:10Z

Weaknesses
  • CWE-427

    Uncontrolled Search Path Element