Vulnerability
Published 2026-09-30
Verified 2026-10-04

Cato Windows SDP Client CVE-2026-10739 (CVSS 4.0 8.5) + CVE-2026-10726: local named-pipe SID → SYSTEM file delete/LPE — patch 6.12.6+

Cato Networks knowledge-base advisory (published 30 September 2026) covers CVE-2026-10726 and CVE-2026-10739 affecting Cato Windows SDP Client versions lower than 6.12.6: a local attacker with access to the installed client can escalate privileges. Fixed in Windows Client 6.12.6 and higher; Cato recommends identifying older clients via Access Overview (filter Cato Client / Windows) and upgrading via Client Rollout / automatic upgrade service. Quarkslab research write-up (1 October 2026) details CVE-2026-10739 as a split-tunnel upload / named-pipe path where a client-supplied SID is used in a filesystem path, enabling arbitrary SYSTEM file delete (and, in their chain, Windows Installer rollback to SYSTEM). Confirmed by Quarkslab on 6.2.0 and 6.4.6; vendor scope is any version before 6.12.6. OpenCVE / Rapid7 list CVE-2026-10739 as CVSS 4.0 8.5 HIGH (AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/…). No wild exploitation stated in the vendor advisory. Primary: Cato KB; research wire: Quarkslab 1 Oct.

Product
Cato Networks SDP Client for Windows
Versions
Affected: Windows Client versions lower than 6.12.6 (Quarkslab confirmed 6.2.0 and 6.4.6). Fixed: 6.12.6 and higher.
CVSS
Exploited in Australia?
unknown
Patch to
Upgrade all Cato Windows Clients to 6.12.6 or later via CMA Client Rollout / automatic upgrade. Use Access Overview to find endpoints still below 6.12.6. No workaround stated beyond upgrading.

Primary: Cato Networks — CVE-2026-10726 & CVE-2026-10739 Windows Client < 6.12.6 (30 Sep 2026) · Vendor: Cato Knowledge Base — upgrade Windows Client to 6.12.6+ · CVE: CVE-2026-10739, CVE-2026-10726 · Quarkslab — Cato VPN Client split-tunnel LPE (CVE-2026-10739) (1 Oct 2026)

vulnerabilities network identity