CVE-2026-10739: Cato Networks SDP Client for Windows is vulnerable to Local Privilege Escalation
Published Sep 30, 2026
·Updated
Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe.
Affected Software
1 affected component
Cato Networks SDP Client for Windows<6.12.6
Event History
Sep 30, 2026
CVE Published
via MITRE·11:37 AM
Data Sourced
via MITRE·11:37 AM
DescriptionWeakness
Data Sourced
via NVD·12:17 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
Who can exploit this issue?
An attacker needs local access to a Windows system running a vulnerable Cato Networks SDP Client. The issue is a local privilege escalation and does not indicate remote exploitation.
2
What versions are affected?
Cato Networks SDP Client for Windows versions earlier than 6.12.6 are affected. Updating to version 6.12.6 or later addresses the affected version range described.
3
What is the impact of successful exploitation?
A local user can cause arbitrary files to be deleted with SYSTEM privileges by exploiting improper validation of a client-supplied SID over a local IPC named pipe.