SecureAge CatchPulse IOCTL saappctl.sys information disclosure
CVE-2026-11459

4.8MEDIUM

Key Information:

Vendor

Secureage

Vendor
CVE Published:
7 June 2026

What is CVE-2026-11459?

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.1. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to information disclosure. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Affected Version(s)

CatchPulse 10.9.0

CatchPulse 10.9.1

References

CVSS V4

Score:
4.8
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Jordanhiggins (VulDB User)
VulDB CNA Team
.