Junglewise Threat Intelligence

CVE-2026-69665: Sky SKYSEA Client View and SKYMEC IT Manager incorrect default permissions

CVE-2026-69665 · Severity: high · CVSS 7.8 · Published 2026-08-25

Technologies: Skymec It Manager, Skysea Client View.

Executive brief

SKYSEA Client View and SKYMEC IT Manager are Windows-based IT management and endpoint control solutions used by organizations to monitor and manage corporate computers. This vulnerability allows any user who can log in locally to a Windows system running these products to execute code with SYSTEM (administrative) privileges, potentially giving attackers complete control over affected computers and the ability to compromise corporate networks.

Technical details

This vulnerability stems from incorrect default file or directory permissions (CWE-276) in the installation of SKYSEA Client View and SKYMEC IT Manager. An authenticated local attacker with user-level privileges can exploit improperly configured permissions to execute arbitrary code with SYSTEM privilege. The attack requires local login access but no user interaction. The root cause lies in the installation process setting overly permissive ACLs on critical application files or directories. Patches and updated versions (SKYSEA Client View 21.310.01a and later, SKYMEC IT Manager fixes via patched modules) are available from the vendor.

Affected products

  • Sky SKYSEA Client View Ver.21.300.12g and earlier
  • Sky SKYMEC IT Manager Ver.2025.205.08a and earlier

Timeline

  • 2026-08-24: disclosed
  • 2026-08-25: advisory
  • 2026-08-24: patched: Updates and patches released by Sky Co., Ltd. via maintenance portals

References