CVE-2026-68959: Path Traversal
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can receive UDP packets from that system. Note that this vulnerability is due to an incomplete fix for CVE-2024-41726.
Affected Software
Event History
Frequently Asked Questions
What access does an attacker need to exploit this issue?
The attacker must be able to log in to a Windows system where an affected product is installed. Exploitation also depends on another Windows system with an affected product being able to receive UDP packets from that logged-in system.
Which systems should be prioritized for review?
Prioritize Windows systems running SKYSEA Client View or SKYMEC IT Manager, especially where affected installations can communicate over UDP with other affected Windows systems. The described attack path involves a compromised or attacker-accessible affected endpoint reaching another affected endpoint.
Does the earlier fix for CVE-2024-41726 fully resolve this risk?
No. This vulnerability is described as resulting from an incomplete fix for CVE-2024-41726.