Junglewise Threat Intelligence

CVE-2026-12374: Cato Networks Cato Client privilege escalation in PrivilegedHelperTool

CVE-2026-12374 · Severity: info · CVSS 6.4 · Published 2026-07-01

Executive brief

A security vulnerability in the Cato Networks macOS client could allow a user who already has limited access to a computer to gain full administrative (root) control. The issue exists in a background service used for high-privilege tasks, which fails to properly verify the identity of software requesting its services. If exploited, an attacker could bypass security controls to install unauthorized software or modify sensitive system files, potentially compromising the entire device.

Technical details

The vulnerability consists of two primary flaws within the PrivilegedHelperTool XPC service of the Cato Client on macOS. First, the service fails to properly validate certificates, allowing a local authenticated attacker to bypass XPC caller verification using a self-signed certificate. Second, a time-of-check time-of-use (TOCTOU) race condition exists during package installation. By combining these flaws, an attacker can perform a symlink swap to redirect file operations, ultimately achieving local privilege escalation to root. The issue is fixed in Cato Client version 5.13.1.

Affected products

  • Cato Networks SDP Client 5.12.0 to 5.13.1 (macOS)

Timeline

  • 2026-07-01: advisory
  • 2026-07-01: disclosed

References