Cato NetworksCVE-2026-10726
Cato Networks SDP Client: improper certificate validation
Medium6.8CVE-2026-10726 · Published Sep 30, 2026
Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.
Affected versions
| Package | Affected | Fixed in |
|---|---|---|
| SDP Client Product | < 6.12.6 | 6.12.6 |
Details and references
More Cato Networks advisories
All Cato Networks| Date | Advisory | Severity | Fixed in |
|---|---|---|---|
| Sep 30 | Cato Networks SDP Client: path traversal | High8.5 | 6.12.6 |
| Jul 1 | Cato Networks SDP Client: improper certificate validation | Medium6.4 | 5.13.1 |