Vulnerability Intelligence Report
CVE-2026-27653
The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges.
No Active Exploit Signals
CVSS Base Score
6.7
MEDIUM
Exploitability:0.8
Impact Score:5.9
EPSS Probability:0.09%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
—
Authentication
—
Weaponization
—
SSVC Action
—
Weaknesses (CWE)
CWE-276 ↗Incorrect default permissions
Affected Products & Versions
| Vendor | Product | Affected Versions |
|---|---|---|
| Soliton Systems K.K. | Soliton SecureBrowser for OneGate | V1.0.0 (affected) |
| Soliton Systems K.K. | Soliton SecureBrowser II | V2.0.0 to V2.0.14 (affected) |
| Soliton Systems K.K. | Soliton SecureWorkspace (formerly WrappingBox) | V1.0.0 to V1.4.7 (affected) |
References & Technical Advisories
No reference links found.
Threat Intelligence Signals
EPSS Score
0.088%
GitHub Advisory
Identity & Timeline
| Status | PUBLISHED |
| Assigning Authority | JPCERT/CC · CERT · Japan |
| Reserved | 2026-02-25T04:39:12 |
| Published | 2026-02-27T05:39:54 |
| Last Updated | 2026-02-27T18:52:30 |
Community Chatter & Buzz