[Japanese]

JVNDB-2026-000097

Multiple vulnerabilities in SKYSEA Client View and SKYMEC IT Manager

Overview

SKYSEA Client View and SKYMEC IT Manager provided by Sky Co., LTD. contains multiple vulnerabilities listed below.
  • Missing authorization (CWE-862) - CVE-2026-66109
  • Path traversal (CWE-22) - CVE-2026-68062
    • This vulnerability is due to an incomplete fix for CVE-2024-41726, as mentioned in JVN#84326763.
  • Path traversal (CWE-25) - CVE-2026-68959
    • This vulnerability is due to an incomplete fix for CVE-2024-41726, as mentioned in JVN#84326763.
  • Stack-based buffer overflow (CWE-121) - CVE-2026-68960
  • Incorrect default permissions (CWE-276) - CVE-2026-69665
CVE-2026-66109, CVE-2026-68062, CVE-2026-68959, CVE-2026-68960
Ruslan Sayfiev and Denis Faiustov of Fujitsu Limitedreported these vulnerabilities to Sky Co., LTD. and coordinated. Sky Co., LTD. and JPCERT/CC published respective advisories in order to notify users of the solutions through JVN.

CVE-2026-69665
Yuji Hayamizu reported this vulnerability to Sky Co., LTD. and coordinated. Sky Co., LTD. and JPCERT/CC published respective advisories in order to notify users of this vulnerability.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 8.5 (High) [IPA Score]
  • Attack Vector: Network
  • Attack Complexity: High
  • Privileges Required: Low
  • User Interaction: None
  • Scope: Changed
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: High
CVSS v4 Severity
Base Metrics: 5.8 (Medium) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): Present
  • Privileges Required (PR): Low
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): None
  • Integrity Impact (VI): None
  • Availability Impact (VA): None
  • Subsequent System Impact
  • Confidentiality Impact (SC): High
  • Integrity Impact (SI): High
  • Availability Impact (SA): High
The above CVSS base scores have been assigned for CVE-2026-68062


CVSS v3 Severity
Base Metrics: 7.8(High) [IPA Score]
  • Access Vector : Local
  • Attack Complexity : Low
  • Privileges Required : Low
  • User Interaction : None
  • Scope : Unchanged
  • Confidentiality Impact : High
  • Integrity Impact : High
  • Availability Impact : High
CVSS v4 Severity
Base Metrics: 8.5 (High) [IPA Score]
  • Access Vector (AV): Local
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): Low
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): High
  • Integrity Impact (VI): High
  • Availability Impact (VA): High
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-66109


CVSS v3 Severity
Base Metrics: 8.5(High) [IPA Score]
  • Access Vector : Network
  • Attack Complexity : High
  • Privileges Required : Low
  • User Interaction : None
  • Scope : Changed
  • Confidentiality Impact : High
  • Integrity Impact : High
  • Availability Impact : High
CVSS v4 Severity
Base Metrics: 5.8 (Medium) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): Present
  • Privileges Required (PR): Low
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): None
  • Integrity Impact (VI): None
  • Availability Impact (VA): None
  • Subsequent System Impact
  • Confidentiality Impact (SC): High
  • Integrity Impact (SI): High
  • Availability Impact (SA): High
The above CVSS base scores have been assigned for CVE-2026-68959


CVSS v3 Severity
Base Metrics: 8.5(High) [IPA Score]
  • Access Vector : Network
  • Attack Complexity : High
  • Privileges Required : Low
  • User Interaction : None
  • Scope : Changed
  • Confidentiality Impact : High
  • Integrity Impact : High
  • Availability Impact : High
CVSS v4 Severity
Base Metrics: 5.8 (Medium) [IPA Score]
  • Access Vector (AV): Network
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): Present
  • Privileges Required (PR): Low
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): None
  • Integrity Impact (VI): None
  • Availability Impact (VA): None
  • Subsequent System Impact
  • Confidentiality Impact (SC): High
  • Integrity Impact (SI): High
  • Availability Impact (SA): High
The above CVSS base scores have been assigned for CVE-2026-68960


CVSS v3 Severity
Base Metrics: 7.8(High) [IPA Score]
  • Access Vector : Local
  • Attack Complexity : Low
  • Privileges Required : Low
  • User Interaction : None
  • Scope : Unchanged
  • Confidentiality Impact : High
  • Integrity Impact : High
  • Availability Impact : High
CVSS v4 Severity
Base Metrics: 8.5 (High) [IPA Score]
  • Access Vector (AV): Local
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): Low
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): High
  • Integrity Impact (VI): High
  • Availability Impact (VA): High
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-69665
Affected Products


Sky Co., LTD.
  • SKYMEC IT Manager 2023.225.03a and 2024.005.10a (CVE-2026-66109, CVE-2026-68960)
  • SKYMEC IT Manager 2024.005.10a (CVE-2026-68062, CVE-2026-68959)
  • SKYMEC IT Manager Ver.2025.205.08a and earlier (CVE-2026-69665)
  • SKYSEA Client View prior to Ver.21.300 (CVE-2026-66109, CVE-2026-68960)
  • SKYSEA Client View Ver.19.300.09h to Ver.21.300 (CVE-2026-68062, CVE-2026-68959)
  • SKYSEA Client View Ver.21.300.12g and earlier (CVE-2026-69665)

Impact

  • An attacker who can log in to the Windows system on which the affected products is installed may execute arbitrary code with SYSTEM privilege (CVE-2026-66109, CVE-2026-69665).
  • An attacker who can log in to a Windows system on which the affected products is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system (CVE-2026-68062, CVE-2026-68959, CVE-2026-68960).
Solution

[Apply the patch]
Apply the patch provided by the developer.
Vendor Information

Sky Co., LTD.
CWE (What is CWE?)

  1. Buffer Errors(CWE-119) [IPA Evaluation]
  2. Path Traversal(CWE-22) [IPA Evaluation]
  3. Permissions(CWE-264) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2026-66109
  2. CVE-2026-68062
  3. CVE-2026-68959
  4. CVE-2026-68960
  5. CVE-2026-69665
References

  1. JVN : JVN#84326763
  2. JVN : JVN#33423625
Revision History

  • [2026/08/24]
      Web page was published