CVE-2026-28267 PUBLISHED

Assigner: jpcert
Reserved: 26.02.2026 Published: 09.03.2026 Updated: 09.03.2026

Multiple i-フィルター products are configured with improper file access permission settings. Files may be created or overwritten in the system directory or backup directory by a non-administrative user.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:N/VI:H/VA:N/SC:N/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor Digital Arts Inc.
Product i-フィルター 10 (Windows version only)
Versions
  • Version prior to Ver.10.02.00 is affected
Vendor Digital Arts Inc.
Product i-フィルター 6.0
Versions
  • Version prior to Ver.6.00.57 is affected
Vendor Digital Arts Inc.
Product i-フィルター for ネットカフェ
Versions
  • Version prior to Ver.6.10.57 is affected
Vendor Digital Arts Inc.
Product i-フィルター for マルチデバイス (Windows version only)
Versions
  • Version prior to Ver.6.00.57 is affected
Vendor Digital Arts Inc.
Product i-フィルター for ZAQ (Windows version only)
Versions
  • Version prior to Ver.6.00.57 is affected
Vendor Digital Arts Inc.
Product i-フィルター for プロバイダー
Versions
  • Version prior to Ver.2.00.30 is affected
Vendor Digital Arts Inc.
Product i-FILTER ブラウザー&クラウド MultiAgent for Windows
Versions
  • Version prior to Ver.4.93R13 is affected
Vendor Digital Arts Inc.
Product DigitalArts@Cloud Agent (for Windows)
Versions
  • Version prior to Ver.1.70R01 is affected
Vendor OPTiM Corporation
Product Optimal Biz Web Filtering Powered by i-FILTER (Windows version)
Versions
  • Version prior to 4.93R13 is affected
Vendor Inventit Inc.
Product MobiConnect i-FILTER Browser Option MultiAgent for Windows
Versions
  • Version prior to Ver.4.93R13 is affected
Vendor Fujitsu Limited
Product i-FILTER Browser & Cloud MultiAgent for Windows
Versions
  • Version prior to Ver.4.93R13 is affected

References

Problem Types