Home › Intelligence › Brief
VULNERABILITY BRIEF🟠 High Vulnerability

Cato VPN Client Split‑Tunnel Feature Enables Local Privilege Escalation (CVE‑2026‑10739)

A local privilege escalation (CVE‑2026‑10739) in Cato Networks’ Windows VPN client allows an attacker to obtain SYSTEM rights through a malformed split‑tunnel upload. The flaw highlights the need for strict privileged‑process controls and timely patching to maintain audit‑ready trust.

LiveThreat™ Intelligence · 📅 October 01, 2026· 📰 blog.quarkslab.com
🟠
Severity
High
VU
Type
Vulnerability
🎯
Confidence
High
🏢
Affected
1 sector(s)
✅
Actions
5 recommended
📰
Source
blog.quarkslab.com

Cato VPN Client Split‑Tunnel Feature Enables Local Privilege Escalation (CVE‑2026‑10739)

What It Is – A newly disclosed vulnerability (CVE‑2026‑10739) in Cato Networks’ SDP Client for Windows allows an unprivileged user to trigger a privileged cleanup routine that can be abused to execute arbitrary code as SYSTEM. The flaw resides in the split‑tunnel upload flow, where a malformed .ccst file causes the privileged service to delete its own temporary file via a named‑pipe interface, opening a path to a Windows Installer rollback that yields a SYSTEM shell.

Exploitability – A proof‑of‑concept exploit has been published and demonstrated on versions 6.2.0, 6.4.6, and any version prior to 6.12.6. The CVSS vector is not disclosed, but the ability to obtain SYSTEM rights on a workstation is considered High severity.

Affected Products – Cato Networks SDP Client (Windows) 6.2.0, 6.4.6, and all releases before 6.12.6.

Why It Matters for Trust & Control Assurance

  • Privileged‑process hygiene – The bug shows how a client‑side component with elevated rights can become an attack vector, underscoring the need for continuous monitoring of privileged services.
  • Evidence of due‑diligence – Demonstrating that your organization patches such flaws promptly provides audit‑ready proof of a robust vulnerability‑management program.
  • Defensible audit trail – Logging of split‑tunnel uploads and named‑pipe activity creates traceable evidence that can satisfy multiple control frameworks (e.g., NIST CSF 2.0 “Protect” domain).

Recommended Actions

  • Deploy Cato Networks’ patch ≥ 6.12.6 immediately on all endpoints.
  • Restrict the VPN client’s service account to the least privileges required; avoid running it as SYSTEM where possible.
  • Enable detailed logging of named‑pipe interactions and split‑tunnel file handling; forward logs to a SIEM for continuous monitoring.
  • Conduct a post‑patch validation scan to confirm the vulnerability is mitigated.
  • Update your asset inventory and control mapping to reflect the privileged‑process control objective.

Source: Quarkslab Blog – Cato VPN Client Split‑Tunnel and Privilege Escalation (CVE‑2026‑10739)

📰 Original Source
http://blog.quarkslab.com/cato-vpn-client-split-tunnel-and-privilege-escalation-cve-2026-10739.html ↗

This LiveThreat Intelligence Brief is an independent analysis. Read the original reporting at the link above.

From the Verisq platform · Trust Operations

Could you prove your access controls held up here?

Credential and access failures map directly to identity and access-control requirements in every major framework. The Verisq AI Trust Operations platform shows where your evidence is thin before an auditor — or an attacker — finds out.

Explore the Verisq AI Trust Operations platform →