CVE-2026-11459 PUBLISHED

SecureAge CatchPulse IOCTL saappctl.sys information disclosure

Assigner: VulDB
Reserved: 06.06.2026 Published: 07.06.2026 Updated: 07.06.2026

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.1. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to information disclosure. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used. The vendor was contacted early about this disclosure but did not respond in any way.

Metrics

CVSS Vector: CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:L/VI:N/VA:N/SC:N/SI:N/SA:N/E:P
CVSS Score: 4.8

Product Status

Vendor SecureAge
Product CatchPulse
Versions
  • Version 10.9.0 is affected
  • Version 10.9.1 is affected

Credits

  • Jordanhiggins (VulDB User) reporter
  • VulDB CNA Team coordinator

References

Problem Types

  • Information Disclosure CWE
  • Improper Access Controls CWE