Missing Authorization Vulnerability in SKYSEA Client View and SKYMEC IT Manager
CVE-2026-66109
8.5HIGH
What is CVE-2026-66109?
A missing authorization vulnerability has been identified in SKYSEA Client View and SKYMEC IT Manager, which may allow an attacker with valid access to the Windows system to execute arbitrary code with SYSTEM privileges. This issue poses a significant risk, enabling unauthorized actions and potentially compromising system integrity. Users and administrators are urged to ensure proper access controls and apply available security updates to mitigate this vulnerability.
Affected Version(s)
SKYMEC IT Manager 2023.225.03a
SKYMEC IT Manager 2024.005.10a
SKYSEA Client View 0
References
CVSS V4
Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
CVSS V3.0
Score:
7.8
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Privileges Required:
Low
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
