CVE-2026-39454

· NIST NVD ↗

SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or place arbitrary files within the installation folder of the product. As a result, arbitrary code may be executed with the administrative privilege.

HIGH
CVSS severity
7.8
CVSS base score
2026-04-20
Published

CWE codes

CWE-276CWE-863

Affected products

skygroup:skymec_it_managerskygroup:skysea_client_view

Sources