CVE-2026-69665
8.5Sky Co., LTD. · SKYSEA Client View and SKYMEC IT Manager
Incorrect default permissions in SKYSEA Client View and SKYMEC IT Manager allow authenticated local users to access or modify sensitive resources.
Executive summary
Incorrect default permissions in SKYSEA Client View and SKYMEC IT Manager could allow a local authenticated attacker to gain unauthorized access to sensitive files or configurations.
Vulnerability
The software contains an issue with incorrect default permissions (CWE-276). An attacker with low-level local access can exploit these weak settings to read or modify sensitive data, leading to a compromise of confidentiality, integrity, and availability.
Business impact
The CVSS score of 8.5 reflects the high potential for impact should an attacker gain unauthorized access to the underlying data or configuration files of these management tools. This could result in the exposure of sensitive network information or the modification of security settings, undermining the overall security posture of the managed infrastructure.
Remediation
Immediate Action: Consult the vendor advisory for specific updates or security patches. Ensure that all deployments are upgraded to the latest version to rectify the insecure default permissions.
Proactive Monitoring: Audit file and registry permissions on systems running the affected software to identify files with overly permissive access settings.
Compensating Controls: Implement strict host-based access controls and ensure the Principle of Least Privilege is applied to all local user accounts on servers hosting these applications.
Exploitation status
Public Exploit Available: Unknown
Analyst recommendation
Given the high severity of this vulnerability, administrators should treat this as a priority update. Applying the vendor-provided patches is the most effective way to ensure that default permissions are correctly hardened across the environment.