Junglewise Threat Intelligence

CVE-2026-39454: Sky Co. SKYSEA Client View and SKYMEC IT Manager privilege escalation

CVE-2026-39454 · Severity: high · CVSS 7.8 · Published 2026-04-20

Technologies: Skygroup Skymec It Manager, Sky Co.,LTD. Skysea Client View. Vendors: Skygroup.

Executive brief

SKYSEA Client View and SKYMEC IT Manager, which are tools used by organizations to manage their IT assets and computers, contain a security flaw in how they are installed on a system. Because the software's installation folder is not properly secured, a standard user without administrative rights can modify or add files to that folder. This could allow an attacker who already has basic access to a computer to take full control of the system with administrative privileges, potentially leading to data theft or complete system compromise.

Technical details

A local privilege escalation vulnerability exists in SKYSEA Client View and SKYMEC IT Manager due to incorrect default permissions (CWE-276) assigned to the product's installation folder. The root cause is an insecure ACL configuration that allows non-administrative users to write, modify, or replace files within the application directory. An attacker with low-privileged local access can exploit this by placing malicious binaries or DLLs in the folder, which are then executed by the application's high-privileged services. This results in arbitrary code execution with administrative or SYSTEM-level privileges. The vendor has released updates and patches to address this issue.

Affected products

  • Sky Co.,LTD. SKYSEA Client View Ver.21.200.07j and earlier
  • Sky Co.,LTD. SKYMEC IT Manager Ver.2024.005.10a and earlier

Timeline

  • 2026-04-20: disclosed
  • 2026-04-20: advisory

References