Arbitrary File Disclosure in Cato Windows SDP Client
CVE-2026-10726

6.8MEDIUM

Key Information:

Vendor
CVE Published:
30 September 2026

What is CVE-2026-10726?

The Cato Windows SDP Client, prior to version 6.12.6, is susceptible to an arbitrary file disclosure vulnerability. This issue arises from inadequate file path validation and the absence of TLS certificate enforcement, which allows a low-privileged local user to manipulate the Windows service running as Local System, leading to unauthorized access to sensitive local files. This vulnerability underscores the importance of stringent security measures to validate file paths and enforce proper authentication protocols.

Affected Version(s)

SDP Client Windows 0 < 6.12.6

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.