CVE-2026-39454Disclosure(skygroup / skymec_it_manager)

LOWCVSS 8.5 · HIGH

Signal is active with 1 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or place arbitrary files within the installation folder of the product. As a result, arbitrary code may be executed with the administrative privilege.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-276CWE-863

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

STABLE

Are you affected?

If you run products in this scope, you should treat this CVE as relevant to your environment.

  • skymec_it_manager
  • skysea_client_view

Threat summary

  • 5 mentions across 2 observed days
  • Momentum state: stable

What's happening

  • Technical details provided in 5 signals
  • Disclosure: 4 classified signals
  • General: 1 classified signal
  • Peaked 1d ago at 4 mentions (2026-04-20); latest day: 1
  • 5 total mentions across 2 days

Affected systems

Vendors
Products
skymec_it_managerskysea_client_view

Deep dive

Activity timeline5 mentions / 2d
01234Mentions · 2026-04-20: 4Mentions · 2026-04-21: 1Technical Details · 2026-04-20: 4Technical Details · 2026-04-21: 104-2004-21
Signal classification2 categories
Disclosure
480.0%
General
120.0%
Referenced assets4 URLs
Classification over time
DateTotalLabels
2026-04-204
Disclosure4
2026-04-211
General1
Full discourse5 posts
  • Autumn Good@autumn_good_35
    Disclosure

    『コンピューター内の実行プロセスに留まる脆弱性であることからリモートで悪意のあるコードを実行させるようなものではございません』 4月20日 Sky株式会社 SKYSEA Client View、SKYMEC IT Manager 【重要】不適切なファイルアクセス権設定の脆弱性(CVE-2026-39454) https://www.skyseaclientview.net/news/260420_01/

    Post summary

    The post announces CVE‑2026‑39454 as an inappropriate file‑access‑rights setting vulnerability that remains local and does not permit remote code execution.

    010401.0K
    6.9K followersView on X
  • K Nakanishi@katsuny3
    General

    【重要】不適切なファイルアクセス権設定の脆弱性(CVE-2026-39454)https://www.skyseaclientview.net/news/260420_01/

    Post summary

    The post simply points to a source that notes an improper file permission issue associated with CVE‑2026‑39454, without providing PoC, exploit, patch, or active exploitation details.

    00020104
    556 followersView on X
  • セキュリティ対策Lab@securityLab_jp
    Disclosure

    SKYSEA Client View・SKYMEC IT Managerに権限昇格の脆弱性(CVE-2026-39454) https://rocket-boys.co.jp/security-measures-lab/skysea-skymec-privilege-escalation-cve-2026-39454/ #セキュリティ対策Lab #security #securitynews

    Post summary

    The tweet announces the discovery of a privilege escalation vulnerability (CVE‑2026‑39454) in SKYSEA Client View/SKYMEC IT Manager, linking to a blog post for further details.

    00000123
    381 followersView on X
  • Vulmon Vulnerability Feed@VulmonFeeds
    Disclosure

    CVE-2026-39454 Arbitrary Code Execution via Improper File Permissions in SKYSEA Client View and SKYMEC IT Manager https://vulmon.com/vulnerabilitydetails?qid=CVE-2026-39454

    Post summary

    The post announces CVE‑2026‑39454, labeling it as an arbitrary code execution flaw caused by improper file permissions in SKYSEA client software, but offers no PoC, exploit, or mitigation details.

    0000059
    4.0K followersView on X
  • CVE@CVEnew
    Disclosure

    CVE-2026-39454 SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrativ… https://www.cve.org/CVERecord?id=CVE-2026-39454

    Post summary

    The text highlights CVE-2026-39454’s issue of improper file permissions in SKYSEA products, but provides no exploit, patch, or active exploitation details.

    0000099
    57.2K followersView on X
CPE platform detail2 entries

2 of 2 entries

PartVendorProductVersionTarget SWTarget HW
Appskygroupskymec_it_manager---
Appskygroupskysea_client_view---

Explore more