CVE-2026-10726
6.8
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Summary
Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.
Affected Software
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Cato Networks | SDP Client | 0 < 6.12.6 | affected |
Weaknesses
- CWE-295: CWE-295 Improper certificate validation
- CWE-73: CWE-73 External control of file name or path
ADP Enrichment
CISA ADP Vulnrichment
- SSVC:
- Exploitation: none
- Automatable: no
- Technical Impact: partial
References
Feedback
Was this page helpful?
Glad to hear it! Please tell us how we can improve.
Sorry to hear that. Please tell us how we can improve.