CVE-2026-10726 PUBLISHED

Cato Windows SDP Client arbitrary file disclosure due to improper TLS certificate validation

Assigner: Cato
Reserved: 03.06.2026 Published: 30.09.2026 Updated: 30.09.2026

Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
CVSS Score: 6.8

Product Status

Vendor Cato Networks
Product SDP Client
Versions Default: unaffected
  • affected from 0 to 6.12.6 (excl.)

References

Problem Types

  • CWE-295 Improper certificate validation CWE
  • CWE-73 External control of file name or path CWE

Impacts

  • CAPEC-126 Path Traversal