OCTOBER 8, 2026
Live Feed
Back to database
Case File

CVE-2026-10739

HIGH · CVSS 8.5 EPSS 0.12%

Source: NVD + CISA KEV + EPSS · Published 2026-09-30 · Last synced 2026-10-08

CyberRota Analysis

AI-Generated

The Cato Networks SDP Client for Windows prior to version 6.12.6 is vulnerable to a local privilege escalation flaw that allows an attacker to delete arbitrary files with SYSTEM privileges due to inadequate validation of a client-supplied SID over a local IPC named pipe. This vulnerability poses a significant risk to system integrity and confidentiality, making it critical for organizations using affected versions of the software to prioritize patching. System administrators and security teams should act promptly to mitigate potential exploitation.

CVE
CVE-2026-10739
Severity
HIGH
CVSS
8.5
EPSS
0.12%
Windows

Original NVD Description

Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe.