GHSA-35v6-rgcf-cgp4Medium

Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability...

Published
September 30, 2026
Last Modified
September 30, 2026

🔗 CVE IDs covered (1)

📋 Description

Cato Windows SDP Client before version 6.12.6 contains an arbitrary file disclosure vulnerability. A low-privileged local user can cause the Windows service, running as Local System, to read and disclose arbitrary local files due to improper file path validation and missing TLS certificate enforcement.

🔗 References (3)