Skip to content
Cato NetworksCVE-2026-10726

Cato Networks SDP Client: improper certificate validation

Medium6.8CVE-2026-10726 · Published Sep 30, 2026

Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.

Cato Networks advisory

Affected versions

PackageAffectedFixed in
SDP Client
Product
< 6.12.66.12.6
Details and references
CVSS 4.0
CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:N/VA:N/SC:L/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Severity from
the vendor (its own CVE record or advisory)
Weakness
CWE-73, CWE-295

More Cato Networks advisories

All Cato Networks
Advisory
Cato Networks SDP Client: path traversal
High8.5Sep 30
Cato Networks SDP Client: improper certificate validation
Medium6.4Jul 1

Critical advisories by email

Wednesdays: the week’s critical and high advisories in the AI and data stack, with the fixed versions. Only in weeks that have some.

Double opt-in. Unsubscribe any time.