CVE-2026-66344
6.7 MEDIUMPublished 2026-08-05 · Updated 2026-08-05
AI risk analysis
- Summary
- The flaw allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by manipulating search paths, posing a significant security risk.
- Exploitability
- Exploitation requires authentication and control over search path elements; moderately difficult given these preconditions.
- Blast radius
- If exploited, the impact could be severe, potentially leading to full system compromise and loss of sensitive data.
- Prioritized remediation
- Update to the latest version of NetKids iMark that addresses this vulnerability or remove the software if it is no longer needed.
rceauth-requiredsystem-privilegespatch-available
Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.
NVD description
NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.
CVSS vector
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
Weaknesses
CWE-427
All references
- https://jvn.jp/en/jp/JVN28045338/
- https://www.istinc.co.jp/dl/jpc/%E3%82%B5%E3%83%BC%E3%83%93%E3%82%B9%E3%81%AE%E5%AE%9F%E8%A1%8C%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%83%91%E3%82%B9%E3%81%8C%E5%BC%95%E7%94%A8%E7%AC%A6%E3%81%A7%E5%9B%B2%E3%81%BE%E3%82%8C%E3%81%A6%E3%81%84%E3%81%AA%E3%81%84%E3%81%93%E3%81%A8%E3%81%AB%E3%82%88%E3%82%8B%E6%A8%A9%E9%99%90%E6%98%87%E6%A0%BC%E3%81%AE%E5%95%8F%E9%A1%8C%E3%81%A8%E5%AF%BE%E5%BF%9C.pdf
- https://www.istinc.co.jp/dl/jpc/DLL%E3%83%95%E3%82%A1%E3%82%A4%E3%83%AB%E3%81%AE%E8%AA%AD%E3%81%BF%E8%BE%BC%E3%81%BF%E3%81%8A%E3%82%88%E3%81%B3%E3%82%A4%E3%83%B3%E3%82%B9%E3%83%88%E3%83%BC%E3%83%AB%E3%83%95%E3%82%A9%E3%83%AB%E3%83%80%E3%81%AE%E3%82%A2%E3%82%AF%E3%82%BB%E3%82%B9%E6%A8%A9%E9%99%90%E3%81%AB%E9%96%A2%E3%81%99%E3%82%8B%E5%95%8F%E9%A1%8C%E3%81%A8%E5%AF%BE%E5%BF%9C.pdf
Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.