Description
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an incomplete fix for CVE-2024-41726.
Published: 2026-08-25
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A path traversal flaw exists in SKYSEA Client View and SKYMEC IT Manager that can be abused by an attacker who has local login access to a Windows system running the affected software. By crafting a malicious path reference, the attacker can cause the application to create or modify files that enable execution of arbitrary code on a different Windows system that also hosts the software and is reachable via UDP. The flaw is a consequence of an incomplete fix for a prior CVE and therefore may not be fully mitigated in all installations.

Affected Systems

The vulnerability is present in Sky Co., LTD: SKYMEC IT Manager and Sky Co., LTD: SKYSEA Client View. Specific product versions are not disclosed in the data provided.

Risk and Exploitability

The CVSS score is 5.8, indicating a medium severity. EPSS information is not available, and the vulnerability is not listed in the CISA KEV catalog. Attack requires the attacker to log into a Windows host with the product installed, then target a separate host that receives UDP packets from it. If these conditions are met, exploit can lead to remote code execution.

Generated by OpenCVE AI on August 25, 2026 at 07:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Ensure the latest software releases from Sky are installed; the vendor has released a patch that addresses the path traversal flaw.
  • Limit UDP traffic to the application by using firewall rules or network segmentation, preventing unauthorized hosts from sending packets that could trigger the vulnerability.
  • If an immediate patch is unavailable, isolate affected systems from untrusted networks and monitor for anomalous file manipulation attempts.

Generated by OpenCVE AI on August 25, 2026 at 07:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Exploit in SKYSEA Client View and SKYMEC IT Manager Enabling Remote Code Execution

Tue, 25 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an incomplete fix for CVE-2024-41726.
Weaknesses CWE-22
References
Metrics cvssV3_0

{'score': 8.5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-25T06:27:54.700Z

Reserved: 2026-08-05T03:02:22.123Z

Link: CVE-2026-68062

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T07:17:10.467

Modified: 2026-08-25T07:17:10.467

Link: CVE-2026-68062

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T07:30:12Z

Weaknesses
  • CWE-22

    Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')