CVE-2026-10726: medium-severity vulnerability in Cato Networks SDP Client
Cato Windows SDP Client arbitrary file disclosure due to improper TLS certificate validation
Published
13Vexday Risk Score
No sign of exploitation. No public exploitation artifact known so far.
ssvc Trackcvss 6.8epss 0.1%
exploitation probability
0.1%top 100% of all CVEs
observed exploitation
nono source reports it
Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N
Affected products
Cato Networks · SDP ClientRelated CVEs — Cato Networks SDP Client
In the same product, most dangerous first.
CVE-2024-6973HIGHRemote Code Execution in Cato Windows SDP client via crafted URLsEPSS 0.8%CVE-2024-6975HIGHCato Networks Windows SDP Client Local Privilege Escalation via openssl configuration fileEPSS 0.3%CVE-2025-3886MEDIUMCatoNetworks CatoClient up to 5.8 PrivilegedHelperTool Race ConditionEPSS 0.2%CVE-2024-6974HIGHCato Networks Windows SDP Client Local Privilege Escalation via self-upgradeEPSS 0.2%CVE-2024-6977MEDIUMCato Networks Windows SDP Client Sensitive data in trace logs can lead to account takeoverEPSS 0.2%CVE-2024-6978MEDIUMCato Networks Windows SDP Client Local root certificates can be installed by low-privileged usersEPSS 0.1%