What is CVE-2026-66839?
A vulnerability related to Unquoted Search Path (CWE-428) has been identified in NetKids iMark. This flaw could allow an authenticated attacker to execute arbitrary code with SYSTEM privileges. Users are advised to run the application in a restricted environment until a patch is provided by the vendor.
Azərbaycanca: NetKids iMark proqramında 'Unquoted Search Path' (CWE-428) zəifliyi aşkar edilib. Bu zəiflik autentifikasiya olunmuş hücumçuya 'SYSTEM' imtiyazları ilə ixtiyari kod icra etməyə imkan verir. İstifadəçilərə təchizatçı tərəfindən yamaq təmin olunana qədər proqramı məhdud mühitdə istifadə etmələri tövsiyə olunur.
FAQ2
What privilege level does the CVE-2026-66839 vulnerability allow for code execution in NetKids iMark?
This Unquoted Search Path (CWE-428) vulnerability allows an authenticated attacker to execute arbitrary code with SYSTEM privileges.
What is the recommended mitigation for NetKids iMark users until a vendor patch is released?
Users are advised to run the application in a restricted environment until a patch is provided by the vendor.
See also6
This explainer is AI-written from source data — skopnix's own reporting on this CVE; CVSS scores, vendors and versions are never invented. See NVD for the official record.