Missing Authorization Vulnerability in SKYSEA Client View and SKYMEC IT Manager
CVE-2026-66109

8.5HIGH

Key Information:

Vendor
CVE Published:
25 August 2026

What is CVE-2026-66109?

A missing authorization vulnerability has been identified in SKYSEA Client View and SKYMEC IT Manager, which may allow an attacker with valid access to the Windows system to execute arbitrary code with SYSTEM privileges. This issue poses a significant risk, enabling unauthorized actions and potentially compromising system integrity. Users and administrators are urged to ensure proper access controls and apply available security updates to mitigate this vulnerability.

Affected Version(s)

SKYMEC IT Manager 2023.225.03a

SKYMEC IT Manager 2024.005.10a

SKYSEA Client View 0

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

CVSS V3.0

Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.