CVE-2026-55979 PUBLISHED

Improper access control check in CatchPulse's named pipe communication interface

Assigner: CSA
Reserved: 18.06.2026 Published: 06.08.2026 Updated: 06.08.2026

An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions. This is limited to operations that enforce more restrictive security policies.

Metrics

CVSS Vector: CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
CVSS Score: 5.2

Product Status

Vendor SecureAge
Product CatchPulse
Versions Default: unaffected
  • Version 10.10.0 and earlier is affected

Solutions

Users and administrators of affected products are advised to update to the latest versions.

Credits

  • Mr Ang Kar Min finder

References