Cato VPN Client Split‑Tunnel Feature Enables Local Privilege Escalation (CVE‑2026‑10739)
What It Is – A newly disclosed vulnerability (CVE‑2026‑10739) in Cato Networks’ SDP Client for Windows allows an unprivileged user to trigger a privileged cleanup routine that can be abused to execute arbitrary code as SYSTEM. The flaw resides in the split‑tunnel upload flow, where a malformed .ccst file causes the privileged service to delete its own temporary file via a named‑pipe interface, opening a path to a Windows Installer rollback that yields a SYSTEM shell.
Exploitability – A proof‑of‑concept exploit has been published and demonstrated on versions 6.2.0, 6.4.6, and any version prior to 6.12.6. The CVSS vector is not disclosed, but the ability to obtain SYSTEM rights on a workstation is considered High severity.
Affected Products – Cato Networks SDP Client (Windows) 6.2.0, 6.4.6, and all releases before 6.12.6.
Why It Matters for Trust & Control Assurance
- Privileged‑process hygiene – The bug shows how a client‑side component with elevated rights can become an attack vector, underscoring the need for continuous monitoring of privileged services.
- Evidence of due‑diligence – Demonstrating that your organization patches such flaws promptly provides audit‑ready proof of a robust vulnerability‑management program.
- Defensible audit trail – Logging of split‑tunnel uploads and named‑pipe activity creates traceable evidence that can satisfy multiple control frameworks (e.g., NIST CSF 2.0 “Protect” domain).
Recommended Actions
- Deploy Cato Networks’ patch ≥ 6.12.6 immediately on all endpoints.
- Restrict the VPN client’s service account to the least privileges required; avoid running it as SYSTEM where possible.
- Enable detailed logging of named‑pipe interactions and split‑tunnel file handling; forward logs to a SIEM for continuous monitoring.
- Conduct a post‑patch validation scan to confirm the vulnerability is mitigated.
- Update your asset inventory and control mapping to reflect the privileged‑process control objective.
Source: Quarkslab Blog – Cato VPN Client Split‑Tunnel and Privilege Escalation (CVE‑2026‑10739)