CVE-2026-11459

LOW

SecureAge CatchPulse IOCTL saappctl.sys information disclosure

Title source: cna
STIX 2.1

Description

A security vulnerability has been detected in SecureAge CatchPulse up to 10.9.3. Impacted is an unknown function in the library saappctl.sys of the component IOCTL Handler. The manipulation leads to information disclosure. Local access is required to approach this attack. The exploit has been disclosed publicly and may be used.

References (7)

Core 7
Core References
Third Party Advisory third-party-advisory
CVE-2026-11459 | CVE Analysis and Report
https://vuldb.com/cve/CVE-2026-11459
Third Party Advisory third-party-advisory
Submit #829131 | SecureAge CatchPulse 10.9.1 Authentication Bypass by Spoofing
https://vuldb.com/submit/829131
Vdb Entry vdb-entry
VDB-369078 | SecureAge CatchPulse IOCTL saappctl.sys information disclosure
https://vuldb.com/vuln/369078
Signature, Permissions Required signature permissions-required
VDB-369078 | CTI Indicators (IOB, IOC, TTP, IOA)
https://vuldb.com/vuln/369078/cti

Scores

CVSS v3 3.3
EPSS 0.0013
EPSS Percentile 3.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation poc
Automatable no
Technical Impact partial

Details

CWE
CWE-200 CWE-284
Status published
Products (4)
SecureAge/CatchPulse 10.9.0
SecureAge/CatchPulse 10.9.1
SecureAge/CatchPulse 10.9.2
SecureAge/CatchPulse 10.9.3
Published Jun 07, 2026
Tracked Since Jun 07, 2026