Loading market data...
← Back to CVE feed

CVE-2026-10726

UNKNOWN View on NVD ↗

Description

Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.

Published: Sep 30, 2026 12:17 UTC Modified: Sep 30, 2026 19:38 UTC