VYPR
High severity7.8NVD Advisory· Published Apr 20, 2026· Updated May 12, 2026

CVE-2026-39454

CVE-2026-39454

Description

SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or place arbitrary files within the installation folder of the product. As a result, arbitrary code may be executed with the administrative privilege.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

4
  • cpe:2.3:a:skygroup:skymec_it_manager:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:skygroup:skymec_it_manager:*:*:*:*:*:*:*:*range: <=2024.005.10a
    • (no CPE)
  • cpe:2.3:a:skygroup:skysea_client_view:*:*:*:*:*:*:*:*+ 1 more
    • cpe:2.3:a:skygroup:skysea_client_view:*:*:*:*:*:*:*:*range: <=21.200.07j
    • (no CPE)

Patches

Vulnerability mechanics

References

2

News mentions

0

No linked articles in our index yet.