CVE-2026-10726

Summary

Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.

Affected Software

VendorProductVersion RangeStatus
Cato NetworksSDP Client0 < 6.12.6affected

Weaknesses

  • CWE-295: CWE-295 Improper certificate validation
  • CWE-73: CWE-73 External control of file name or path

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: partial

References