CVE-2026-10726mediumCWE-295CWE-73

CVE-2026-10726: medium-severity vulnerability in Cato Networks SDP Client

Cato Windows SDP Client arbitrary file disclosure due to improper TLS certificate validation

Published

13Vexday Risk Score

No sign of exploitation. No public exploitation artifact known so far.

ssvc Trackcvss 6.8epss 0.1%
exploitation probability
0.1%top 100% of all CVEs
observed exploitation
nono source reports it
Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N