Medium severityNVD Advisory· Published Sep 30, 2026
CVE-2026-10726
CVE-2026-10726
Description
Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
1- Range: <6.12.6
Patches
Vulnerability mechanics
References
1News mentions
0No linked articles in our index yet.