CVE-2026-68062: Improper limitation of a pathname to a restricted directory ('Path Traversal') in Sky Co., LTD. SKYSEA Client View
Description
CVE-2026-68062 is a path traversal vulnerability in SKYSEA Client View and SKYMEC IT Manager. It allows an attacker with login access to a Windows system running the affected software to potentially execute arbitrary code on another Windows system that also has the affected products installed and can receive UDP packets from the first system. This vulnerability stems from an incomplete fix of a previous issue (CVE-2024-41726).
CVSS v3.0
Score 8.5high
Affected software
Sky Co., LTD.
SKYSEA Client View
Sky Co., LTD.
SKYMEC IT Manager
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability involves improper limitation of a pathname to a restricted directory, enabling path traversal attacks. Exploitation requires the attacker to have login privileges on a Windows system with the affected software installed. Successful exploitation could lead to remote code execution on another Windows system that has the affected products installed and is reachable via UDP packets from the compromised system. This issue is a regression or incomplete fix related to CVE-2024-41726.
Potential Impact
An attacker with low privileges on a compromised Windows system can leverage this vulnerability to execute arbitrary code on a second Windows system running the affected software and reachable via UDP. This could lead to full compromise of the target system, including confidentiality, integrity, and availability impacts as indicated by the CVSS score of 8.5 (high severity).
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. No official fix or temporary workaround is currently documented. Until a fix is available, restrict login access to systems running the affected software and monitor for suspicious activity involving UDP communications between systems with SKYSEA Client View or SKYMEC IT Manager installed.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- jpcert
- Date Reserved
- 2026-08-05T03:02:22.123Z
- Cvss Version
- 3.0
- State
- PUBLISHED
Threat ID: 6a8d3833acd9273b49cafc37
Added to database: 08/25/2026, 06:37:39 UTC
Last enriched: 09/10/2026, 07:22:10 UTC
Last updated: 10/09/2026, 18:48:22 UTC
Views: 68
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.