{"id":"CVE-2026-10739","title":"Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe.","summary":"Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe.","severity":"high","cvss":8.5,"cvssVector":"CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cwe":["CWE-23","CWE-59","CWE-73"],"vendor":"Cato Networks","product":"SDP Client","affected":["sdp_client < 6.12.6"],"published":"2026-09-30","updated":"2026-09-30","sourceUpdated":"2026-09-30T12:17:12.963","source":"NVD","sourceUrl":"https://nvd.nist.gov/vuln/detail/CVE-2026-10739","references":[{"url":"https://knowledge.catonetworks.com/docs/cve-2026-10726-cve-2026-10739-impacts-windows-client-versions-lower-than-6126","label":"2505284f-8ffb-486c-bf60-e19c1097a90b"}],"tags":["nvd","cve.org"],"cvssSource":"cna","ingestedAt":"2026-09-30T12:02:58.587Z","ssvc":{"exploitation":"none","automatable":"no","technicalImpact":"total","timestamp":"2026-09-30T14:27:45.762535Z"},"slug":"CVE-2026-10739","body":"## Overview\n\nCato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe.\n\n## Remediation\n\nRefer to the linked advisories for vendor-supplied fixes and affected version ranges.","depth":"twilight","depthScore":47,"depthScoreParts":{"impact":46.8,"likelihood":0,"exploitation":0,"ransomware":0},"changes":[]}