PT-2026-103124 · Cato Networks · Sdp Client For Windows

CVE-2026-10739

·

Published

2026-09-30

·

Updated

2026-10-01

CVSS v4.0

8.5

High

VectorAV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Name of the Vulnerable Software and Affected Versions Cato Networks SDP Client for Windows versions prior to 6.12.6
Description A local privilege escalation issue exists due to improper validation of a client-supplied Security Identifier (SID) over a local Inter-Process Communication (IPC) named pipe. A low-privileged user can send a SplitTunnelUpload command via the .pipecato-VPN endpoint to the winvpnclient.cli.exe process, which runs with SYSTEM privileges. By providing a crafted UserSidString variable within the UiRegister protobuf message containing path traversal sequences (e.g., ..), an attacker can redirect file operations outside the intended directory. This allows the deletion of arbitrary files with SYSTEM privileges. This primitive can be combined with symlink redirects to target directories like C:Config.Msi to achieve a full SYSTEM shell.
Recommendations Update Cato Networks SDP Client for Windows to version 6.12.6.

Fix

LPE

Link Following

Relative Path Traversal

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-10739

Affected Products

Sdp Client For Windows