Description
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an incomplete fix for CVE-2024-41726.
Published: 2026-08-25
Score: 5.8 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is a path traversal flaw present in SKYSEA Client View and SKYMEC IT Manager. An attacker who logs into a Windows system running the affected product can use the flaw to traverse directories and cause the application to read or write unauthorized files. Because the affected products also process UDP packets, an attacker may execute arbitrary code on another Windows system that simultaneously has the products installed and can receive UDP traffic from the compromised host. The weakness corresponds to CWE‑25, reflecting improper access to array elements or pointers.

Affected Systems

Affected vendors include Sky Co., LTD., with products SKYSEA Client View and SKYMEC IT Manager. No specific version information was supplied. Users of any installation of these products on Windows should consider the possibility of the flaw until a patch is released.

Risk and Exploitability

The CVSS score of 5.8 indicates a medium severity rating. The EPSS score is not available, and the vulnerability is not listed in the CISA KEV catalog. The flaw requires legitimate login on a Windows host, but as soon as the attacker can trigger the path traversal, code can be executed on a remote satellite system that accepts UDP messages. The official advisory notes that the issue originates from an incomplete fix of CVE‑2024‑41726, possibly indicating a recurring flaw. Attackers would likely exploit it by sending crafted UDP packets after logging in, so the vector is likely remote but requires authentication on the local machine.

Generated by OpenCVE AI on August 25, 2026 at 07:20 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the vendor‑supplied patch or upgrade SKYSEA Client View and SKYMEC IT Manager to the latest release.
  • Disable or restrict UDP traffic directed at the affected services, or block the specific UDP port used by these products.
  • Enforce least privilege for local Windows accounts and require multi‑factor authentication to limit the ability of an attacker to log in and trigger the traversal.
  • Monitor Windows Event logs for abnormal path traversal or UDP activity and alert on repeated failures.

Generated by OpenCVE AI on August 25, 2026 at 07:20 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Tue, 25 Aug 2026 07:45:00 +0000

Type Values Removed Values Added
Title Path Traversal Enables Remote Code Execution via UDP in SkyCo Products

Tue, 25 Aug 2026 06:45:00 +0000

Type Values Removed Values Added
Description SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an incomplete fix for CVE-2024-41726.
Weaknesses CWE-25
References
Metrics cvssV3_0

{'score': 8.5, 'vector': 'CVSS:3.0/AV:N/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H'}

cvssV4_0

{'score': 5.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:N/VI:N/VA:N/SC:H/SI:H/SA:H'}


Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: jpcert

Published:

Updated: 2026-08-25T06:27:59.698Z

Reserved: 2026-08-05T03:02:22.910Z

Link: CVE-2026-68959

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-08-25T07:17:10.600

Modified: 2026-08-25T07:17:10.600

Link: CVE-2026-68959

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-25T07:30:12Z

Weaknesses
  • CWE-25

    Path Traversal: '/../filedir'