CVE-2026-10739

Summary

Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe.

Affected Software

VendorProductVersion RangeStatus
Cato NetworksSDP Client0 < 6.12.6affected

Weaknesses

  • CWE-23: CWE-23 Relative path traversal
  • CWE-59: CWE-59 Improper link resolution before file access ('link following')
  • CWE-73: CWE-73 External control of file name or path

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: none
    • Automatable: no
    • Technical Impact: total

References