CVE-2026-55978
Received Received - Intake

Improper Access Control in CatchPulse Kernel Filter Port

Vulnerability report for CVE-2026-55978, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-08-06

Last updated on: 2026-08-06

Assigner: CSA

Description

An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter communication port and bypass CatchPulse's security policy enforcement.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-08-06
Last Modified
2026-08-06
Generated
2026-08-16
AI Q&A
2026-08-06
EPSS Evaluated
2026-08-15
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
catchpulse catchpulse *

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-284 The product does not restrict or incorrectly restricts access to a resource from an unauthorized actor.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This vulnerability is an improper access control issue in CatchPulse that allows a non-administrative local attacker to connect to an unrestricted kernel filter communication port. This bypasses CatchPulse's security policy enforcement, potentially enabling unauthorized actions.

Detection Guidance

The provided CVE data does not include specific detection methods or commands for identifying this vulnerability on a network or system. Users should check for unauthorized connections to CatchPulse's kernel filter communication port and verify that the software is updated to version 10.10.0 or later.

Impact Analysis

An attacker could exploit this to bypass security policies, gain unauthorized access to sensitive system functions, or perform actions that should be restricted. This could lead to data breaches, system compromise, or other malicious activities depending on the attacker's goals.

Compliance Impact

This vulnerability could allow unauthorized access to sensitive system components, potentially leading to data breaches or policy violations. Such breaches may impact compliance with regulations like GDPR or HIPAA by exposing protected data or failing to enforce security policies.

Mitigation Strategies

Apply vendor-provided patches or updates for CatchPulse to address the improper access control issue. Restrict local user permissions to prevent unauthorized access to kernel filter communication ports. Monitor system logs for suspicious connection attempts to unrestricted ports.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-55978. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart