← Back to search

CVE-2026-66839

6.7 MEDIUM

Published 2026-08-05 · Updated 2026-08-05

AI risk analysis

Summary
The vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges by exploiting an Unquoted Search Path or Element flaw.
Exploitability
Exploitation requires authentication and specific conditions; it is moderately difficult due to these prerequisites.
Blast radius
If exploited, the impact could be severe as it grants full control over the system.
Prioritized remediation
Update NetKids iMark software to the latest version that addresses this vulnerability.
rceauth-requiredsystem-privileges

Analysis generated locally by qwen2.5:7b-instruct (no data left the box). AI-assisted — verify against primary sources before acting.

NVD description

NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.

CVSS vector

CVSS:3.0/AV:L/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H

Weaknesses

CWE-428

All references

Source data: NVD (nvd.nist.gov), public domain. Exploit-DB.ai adds local AI analysis for defensive use only.