CVE-2026-10739
Received Received - Intake

Local File Deletion in Cato Networks SDP Client for Windows

Vulnerability report for CVE-2026-10739, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-30

Last updated on: 2026-09-30

Assigner: Cato

Description

Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-30
Last Modified
2026-09-30
Generated
2026-09-30
AI Q&A
2026-09-30
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 1 associated CPE
Vendor Product Version / Range
cato_networks sdp_client to 6.12.6 (exc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-23 The product uses external input to construct a pathname that should be within a restricted directory, but it does not properly neutralize sequences such as ".." that can resolve to a location that is outside of that directory.
CWE-73 The product allows user input to control or influence paths or file names that are used in filesystem operations.
CWE-59 The product attempts to access a file based on the filename, but it does not properly prevent that filename from identifying a link or shortcut that resolves to an unintended resource.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-10739 is a vulnerability in Cato Networks SDP Client for Windows versions before 6.12.6. It allows a local user to delete arbitrary files with SYSTEM privileges by exploiting improper validation of a client-supplied SID over a local IPC named pipe.

Detection Guidance

Detecting this vulnerability requires checking the installed version of the Cato Networks SDP Client for Windows. Compare the installed version against 6.12.6. If the version is lower, the system is vulnerable. Use the Cato Management Application (CMA) or check the client's version via the Windows Control Panel or installed programs list.

Impact Analysis

Attackers with access to the Windows Client could escalate privileges and delete critical system files, potentially causing system instability or denial of service. This could lead to unauthorized data access or system compromise if exploited.

Compliance Impact

The vulnerability allows local privilege escalation to SYSTEM level, which could lead to unauthorized access or modification of sensitive data. This may violate compliance requirements for data protection standards like GDPR (data integrity and confidentiality) and HIPAA (unauthorized access to protected health information).

Mitigation Strategies

Upgrade the Cato Networks SDP Client for Windows to version 6.12.6 or higher immediately. This can be done manually or via the Cato upgrade service. Ensure all Windows Clients are updated to prevent privilege escalation attacks.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-10739. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart