Path traversal in SKYSEA Client View and SKYMEC IT Manager - CVE-2026-68062
Published: August 24, 2026
Vulnerability identifier: #VU144616
CSH Severity: Medium
CVSS v4: 7.7 [CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-68062
CWE-ID: CWE-22
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to perform directory traversal attacks.
The vulnerability exists due to input validation error when processing directory traversal sequences. A remote user can send a specially crafted HTTP request and upload arbitrary files on the system, leading to arbitrary code execution.
Affected software
SKYSEA Client View
SKYMEC IT Manager
SKYMEC IT Manager
How to mitigate CVE-2026-68062
Install updates from vendor's website.
SKYSEA Client View - update to 21.310.01a