CVE-2026-27653: Soliton Securebrowser For Onegate

Medium severity, CVSS 6.7. EPSS: 0.1% chance of exploitation in the next 30 days.

The installers for multiple products provided by Soliton Systems K.K. contain an issue with incorrect default permissions, which may allow arbitrary code to be executed with SYSTEM privileges.

Affected products

  • Soliton Securebrowser For Onegate: version 1.0.0 only
  • Soliton Securebrowser Ii: from 2.0.0, before 2.0.15 (fixed in 2.0.15)
  • Soliton Secureworkspace: from 1.0.0, before 1.4.8 (fixed in 1.4.8)

Published 2026-02-27. Last modified 2026-06-17.