← Back to search

CVE-2026-66344

6.7 MEDIUM

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The flaw allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by manipulating search paths, posing a significant security risk.
Exploitability
Exploitation requires authentication and control over search path elements; moderately difficult given these preconditions.
Blast radius
If exploited, the impact could be severe, potentially leading to full system compromise and loss of sensitive data.
Prioritized remediation
Update to the latest version of NetKids iMark that addresses this vulnerability or remove the software if it is no longer needed.
rceauth-requiredsystem-privilegespatch-available

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Uncontrolled Search Path Element vulnerability (CWE-427). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.

CVSS vector

CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H

Weaknesses

CWE-427

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.