6.7
CVE-2026-27653
- EPSS 0.01%
- Veröffentlicht 27.02.2026 05:39:54
- Zuletzt bearbeitet 17.03.2026 15:48:27
- Quelle vultures@jpcert.or.jp
- CVE-Watchlists
- Unerledigt
The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges.
Daten sind bereitgestellt durch National Vulnerability Database (NVD)
Soliton ≫ Securebrowser For Onegate Version1.0.0 SwPlatformwindows
Soliton ≫ Securebrowser Ii SwPlatformwindows Version >= 2.0.0 < 2.0.15
Soliton ≫ Secureworkspace Version >= 1.0.0 < 1.4.8
| Typ | Quelle | Score | Percentile |
|---|---|---|---|
| EPSS | FIRST.org | 0.01% | 0.01 |
| Quelle | Base Score | Exploit Score | Impact Score | Vector String |
|---|---|---|---|---|
| nvd@nist.gov | 6.7 | 0.8 | 5.9 |
CVSS:3.1/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
|
| vultures@jpcert.or.jp | 5.4 | 0 | 0 |
CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
|
| vultures@jpcert.or.jp | 6.7 | 0.8 | 5.9 |
CVSS:3.0/AV:L/AC:H/PR:L/UI:R/S:U/C:H/I:H/A:H
|
CWE-276 Incorrect Default Permissions
During installation, installed file permissions are set to allow anyone to modify those files.
CWE-863 Incorrect Authorization
The product performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check.