CVE-2026-66839 Details
Description
NetKids iMark, provided by Integrated Systems Technologies, Inc., contains an Unquoted Search Path or Element vulnerability (CWE-428). An authenticated attacker may exploit this vulnerability to execute arbitrary code with SYSTEM privileges.
A vulnerability allowing arbitrary code execution with SYSTEM privileges has been identified in NetKids iMark, provided by Integrated Systems Technologies, Inc. This issue arises from an unquoted search path vulnerability, where the application does not properly enclose the executable path in quotes. As a result, an authenticated attacker could exploit this flaw by placing a malicious executable in a directory referenced by the service, leading to unauthorized code execution with elevated privileges.
Users are advised to update to the latest version of NetKids iMark once it is released. Until then, the executable path for the 'nkmsgService' should be manually updated to include quotes, and the service should be restarted.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Aug 5, 2026CISA-ADP
Assessed Aug 5, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-428 | Unquoted Search Path or Element | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Integrated Systems Technologies NetKids iMark | <= V5.2.5.0 |
CPE
Remediation
| |
Change History
2 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Aug 5, 2026 | CVE Modified | CISA-ADP |
| Aug 5, 2026 | New CVE Received | [email protected] |
Volerion