CVE-2026-27653
EUVD-2026-899827.02.2026, 06:17
The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges.Enginsight
Affected Products (NVD)
| Vendor | Product | Version |
|---|---|---|
| soliton | securebrowser_for_onegate | 1.0.0 |
| soliton | securebrowser_ii | 2.0.0 ≤ 𝑥 < 2.0.15 |
| soliton | secureworkspace | 1.0.0 ≤ 𝑥 < 1.4.8 |
𝑥
= Vulnerable software versions
Common Weakness Enumeration
- CWE-276 - Incorrect Default PermissionsDuring installation, installed file permissions are set to allow anyone to modify those files.
- CWE-863 - Incorrect AuthorizationThe software performs an authorization check when an actor attempts to access a resource or perform an action, but it does not correctly perform the check. This allows attackers to bypass intended access restrictions.