Junglewise Threat Intelligence

CVE-2025-8590: AKCE Software Technology SKSPro directory indexing information exposure

CVE-2025-8590 · Severity: high · CVSS 7.5 · Published 2026-02-03

Technologies: AKCE Software Technology R&D Industry and Trade Inc. Skspro.

Executive brief

AKCE SKSPro is a software solution used for managing corporate operations. A security flaw in the system allows unauthorized individuals to view the contents of server directories that should be hidden. This could lead to the exposure of sensitive configuration files, source code, or user data, potentially providing attackers with information needed for further system compromises.

Technical details

A vulnerability in AKCE Software Technology SKSPro (versions through 07012026) allows for unauthorized directory indexing. This is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). An unauthenticated remote attacker can exploit this by sending a simple network request to the server, allowing them to browse the file system structure and access sensitive files that are not explicitly protected. The vulnerability stems from a failure to disable directory listing on the web server component. A CVSS 3.1 base score of 7.5 has been assigned, reflecting high confidentiality impact with no requirement for user interaction or privileges.

Affected products

  • AKCE Software Technology R&D Industry and Trade Inc. SKSPro through 07012026

Timeline

  • 2026-02-03: advisory: Initial publication by TR-CERT/USOM
  • 2026-06-05: other: NVD record updated

References