Information Leakage in Netskope Client for Windows
CVE-2026-15710

6.8MEDIUM

Key Information:

Vendor

Netskope

Vendor
CVE Published:
11 September 2026

What is CVE-2026-15710?

An information leakage vulnerability exists in the Endpoint DLP component of the Netskope Client for Windows, specifically in the epdlpdrv.sys driver before version R141. This issue arises from inadequate token-based message validation on the internal communication channel between the user-space hook DLL and the kernel driver. Consequently, local unprivileged processes can send unauthorized queries, compromising security. Furthermore, a reply buffer managed by the port message handler is improperly initialized, which can lead to the leakage of residual kernel pool memory from prior allocations. This vulnerability may allow an attacker to enumerate DLP configurations and feature flags, extract live session tokens, and read kernel memory fragments related to other users' operations.

Affected Version(s)

Endpoint DLP Windows 0

References

CVSS V4

Score:
6.8
Severity:
MEDIUM
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Local
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

Nuttakorn Tungpoonsup (KBTG Cybersecurity Research Engineer)
Jirawat Siengphao (KBTG Cybersecurity Research Engineer)
Khanatip Vanjongkham (KBTG Cybersecurity Research Engineer)
Waris Damkham (KBTG Cybersecurity Research Engineer)
.