CVE-2026-10739

LOWCVSS 8.5 · HIGH

Signal is active with 3 mentions in latest observed window

Immediate actions

  • Track advisory updates for patch or workaround availability

Recommended action window: Monitor and triage in normal cycle

NVD description

Cato Networks SDP Client for Windows before 6.12.6 allows a local user to delete arbitrary files with SYSTEM privileges via improper validation of a client-supplied SID over a local IPC named pipe.

0.0/ 10 priority

Sources & remediation

Weakness type (CWE)
CWE-23CWE-59CWE-73

Priority

LOW

Exploitation

NONE

PoC

NONE

Patch

NONE

Momentum

NONE

Threat summary

  • 3 mentions across 1 observed day

What's happening

  • 3 total mentions across 1 day

Deep dive

Activity timeline3 mentions / 1d
01223Mentions · 2026-10-01: 310-01
Referenced assets1 URL
Full discourse3 posts
  • quarkslab@quarkslab

    Not an antivirus product this time, but we couldn't pass it up 🙈 @CatoNetworks said: route with split tunneling. @kaluche_ heard: root with split tunneling. Check out CVE-2026-10739, a LPE vulnerability in the Cato VPN Client for Windows ➡️ https://blog.quarkslab.com/cato-vpn-client-split-tunnel-and-privilege-escalation-cve-2026-10739.html https://t.co/y2c7I4jbtx

    15118101.5K
    12.6K followersView on X
  • DFIR Radar@DFIR_Radar

    CVE-2026-10739: Local privilege escalation in Cato Networks SDP Client for Windows chains a protobuf SID path traversal, a privileged SYSTEM delete, and a symlink redirect into a full SYSTEM shell. Patch threshold is any version below 6.12.6. Key findings: - The attack surface is the split-tunnel file upload feature. The low-privileged GUI sends a SplitTunnelUpload command over the named pipe \\.\pipe\cato-VPN to winvpnclient.cli.exe running as NT AUTHORITY\SYSTEM. The UserSidString field in the UiRegister protobuf message is attacker-controlled and is used verbatim to build the output path ccst_<SID>.stp under ProgramData\CatoNetworks\SDPClient\ST. Because ..\ sequences are not stripped, a crafted SID like \\..\\..\\..\\tmp\\foobar redirects the write or delete outside the split-tunnel directory entirely. - The named pipe enforces a certificate check: the service calls GetNamedPipeClientProcessId, resolves the client image with QueryFullProcessImageNameW, and verifies the Cato signing certificate via memcmp against expected certificate material. A random process is rejected. The bypass is manual DLL mapping into a legitimately signed CatoClient.exe process, so the IPC gate sees a valid Cato-signed origin and passes the check without any file modification. - The weaponized primitive is the cleanup delete path, not the write. When a readable but invalid .ccst file is uploaded, winvpnclient.cli.exe deletes the generated .stp artifact as SYSTEM. Combined with the path traversal, the attacker controls exactly what SYSTEM deletes. A junction and an RPC Control object directory symlink redirect that delete to C:\Config.Msi, invoking the well-documented Windows Installer MSI rollback escalation chain and landing a SYSTEM shell. Procmon confirms the delete hitting Config.Msi before the MSI stage executes. - Affected versions are confirmed on 6.2.0 and 6.4.6; the vendor states all versions before 6.12.6 are vulnerable. CVE-2026-10739 was assigned 2026-09-30. The vendor published a security announcement to customers the same day. Quarkslab's coordinated disclosure ran from 2026-06-02 to today's publication. Responder takeaway: On any Windows endpoint running Cato Client, look for winvpnclient.cli.exe performing file deletes outside ProgramData\CatoNetworks\SDPClient\ST, especially touching C:\Config.Msi or junction points under C:\poc or similar attacker-created directories. Hunt for CatoClient.exe spawning unexpected child processes or hosting injected threads, particularly ones opening \\.\pipe\cato-VPN from an unusual call stack. The path traversal payload would appear in pipe traffic as a UiRegister message (command ID 34, body field 25) with a UserSidString containing backslash sequences rather than a valid SID format. Prioritize upgrading to 6.12.6 across your endpoint inventory, but first check whether any endpoint has already seen a Config.Msi deletion event paired with Cato process activity. The PoC payload source CatoPipePayload.c is referenced in the Quarkslab report. #DFIR_Radar

    11010145
    2.0K followersView on X
  • DFIR Radar@DFIR_Radar

    Source: https://blog.quarkslab.com/cato-vpn-client-split-tunnel-and-privilege-escalation-cve-2026-10739.html

    0000051
    2.0K followersView on X

Explore more