Local File Deletion Vulnerability in Cato Networks SDP Client for Windows
CVE-2026-10739

8.5HIGH

Key Information:

Vendor
CVE Published:
30 September 2026

What is CVE-2026-10739?

The Cato Networks SDP Client for Windows versions prior to 6.12.6 is susceptible to a security flaw that allows local users to delete arbitrary files. This vulnerability arises from inadequate validation of a client-supplied Security Identifier (SID) over a local Inter-Process Communication (IPC) pipe, potentially leading to unauthorized file manipulation with SYSTEM privileges, which poses a significant security risk to affected systems.

Affected Version(s)

SDP Client Windows 0 < 6.12.6

References

CVSS V4

Score:
8.5
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.