[Japanese]

JVNDB-2026-000108

Multiple vulnerabilities in NetKids iMark

Overview

NetKids iMark provided by Integrated Systems Technologies, Inc. contains multiple vulnerabilities listed below:
  • Uncontrolled search path element (CWE-427) - CVE-2026-66344
  • Unquoted search path or element (CWE-428) - CVE-2026-66839
Kazuma Matsumoto of GMO Cybersecurity by IERAE, Inc. reported these vulnerabilities to IPA.
JPCERT/CC coordinated with the developer under Information Security Early Warning Partnership.
CVSS Severity (What is CVSS?)

CVSS V3 Severity:
Base Metrics 6.7 (Medium) [IPA Score]
  • Attack Vector: Local
  • Attack Complexity: Low
  • Privileges Required: High
  • User Interaction: None
  • Scope: Unchanged
  • Confidentiality Impact: High
  • Integrity Impact: High
  • Availability Impact: High
CVSS v4 Severity
Base Metrics: 8.4 (High) [IPA Score]
  • Access Vector (AV): Local
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): None
  • Privileges Required (PR): High
  • User Interaction (UI): None
  • Vulnerable System Impact
  • Confidentiality Impact (VC): High
  • Integrity Impact (VI): High
  • Availability Impact (VA): High
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-66839


CVSS v3 Severity
Base Metrics: 6.7(Medium) [IPA Score]
  • Access Vector : Local
  • Attack Complexity : High
  • Privileges Required : Low
  • User Interaction : Required
  • Scope : Unchanged
  • Confidentiality Impact : High
  • Integrity Impact : High
  • Availability Impact : High
CVSS v4 Severity
Base Metrics: 5.4 (Medium) [IPA Score]
  • Access Vector (AV): Local
  • Attack Complexity (AC): Low
  • Attack Requirements (AT): Present
  • Privileges Required (PR): Low
  • User Interaction (UI): Passive
  • Vulnerable System Impact
  • Confidentiality Impact (VC): High
  • Integrity Impact (VI): High
  • Availability Impact (VA): High
  • Subsequent System Impact
  • Confidentiality Impact (SC): None
  • Integrity Impact (SI): None
  • Availability Impact (SA): None
The above CVSS base scores have been assigned for CVE-2026-66344
Affected Products


Integrated Systems Technologies, Inc.
  • NetKids iMark versions V5.2.5.0 and earlier

Impact

  • Arbitrary code may be executed with SYSTEM privilege by an attacker who logged in to the affected device (CVE-2026-66344).
  • Arbitrary code may be executed with SYSTEM privilege by an attacker with write access to the system folder (CVE-2026-66839).
Solution

[Apply the Workaround]
The developer plans to provide an update addressing these vulnerabilities.
Until the update is available, apply the workaround based on the information provided by the developer.
Vendor Information

Integrated Systems Technologies, Inc.
CWE (What is CWE?)

  1. No Mapping(CWE-Other) [IPA Evaluation]
CVE (What is CVE?)

  1. CVE-2026-66344
  2. CVE-2026-66839
References

  1. JVN : JVN#28045338
  2. JVN : JVNTA#91240916
Revision History

  • [2026/08/05]
      Web page was published