{"dataType":"CVE_RECORD","dataVersion":"5.2","cveMetadata":{"cveId":"CVE-2026-12374","assignerOrgId":"2505284f-8ffb-486c-bf60-e19c1097a90b","state":"PUBLISHED","assignerShortName":"Cato","dateReserved":"2026-06-16T07:28:42.180Z","datePublished":"2026-07-01T14:07:28.896Z","dateUpdated":"2026-07-01T15:07:24.153Z"},"containers":{"cna":{"providerMetadata":{"orgId":"2505284f-8ffb-486c-bf60-e19c1097a90b","shortName":"Cato","dateUpdated":"2026-07-01T14:07:28.896Z"},"title":"Improper XPC caller certificate validation and TOCTOU race condition in macOS PrivilegedHelperTool","problemTypes":[{"descriptions":[{"lang":"en","cweId":"CWE-295","description":"CWE-295 Improper certificate validation","type":"CWE"}]},{"descriptions":[{"lang":"en","cweId":"CWE-367","description":"CWE-367 Time-of-check time-of-use (TOCTOU) race condition","type":"CWE"}]}],"impacts":[{"capecId":"CAPEC-233","descriptions":[{"lang":"en","value":"CAPEC-233 Privilege Escalation"}]}],"affected":[{"vendor":"Cato Networks","product":"SDP Client","platforms":["MacOS"],"modules":["PrivilegedHelperTool"],"versions":[{"status":"affected","version":"5.12.0","lessThan":"5.13.1","versionType":"semver"}],"defaultStatus":"unaffected"}],"descriptions":[{"lang":"en","value":"Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local authenticated attacker to escalate privileges to root via a self-signed certificate that bypasses the XPC caller verification and a symlink swap during package installation.","supportingMedia":[{"type":"text/html","base64":false,"value":"Improper certificate validation and a time-of-check time-of-use (TOCTOU) race condition in the PrivilegedHelperTool XPC service in Cato Client before v.5.13.1 on macOS allows a local authenticated attacker to escalate privileges to root via a self-signed certificate that bypasses the XPC caller verification and a symlink swap during package installation.<br>"}]}],"references":[{"url":"https://support.catonetworks.com/hc/en-us/articles/37284626576413-Security-Vulnerability-CVE-2026-12374-that-Impacts-macOS-Client-Versions-Lower-than-5-13-1"}],"metrics":[{"format":"CVSS","scenarios":[{"lang":"en","value":"GENERAL"}],"cvssV4_0":{"attackVector":"LOCAL","attackComplexity":"LOW","attackRequirements":"PRESENT","privilegesRequired":"LOW","userInteraction":"NONE","vulnConfidentialityImpact":"HIGH","subConfidentialityImpact":"NONE","vulnIntegrityImpact":"HIGH","subIntegrityImpact":"NONE","vulnAvailabilityImpact":"HIGH","subAvailabilityImpact":"NONE","exploitMaturity":"PROOF_OF_CONCEPT","Safety":"NOT_DEFINED","Automatable":"YES","Recovery":"USER","valueDensity":"CONCENTRATED","vulnerabilityResponseEffort":"LOW","providerUrgency":"AMBER","version":"4.0","baseSeverity":"MEDIUM","baseScore":6.4,"vectorString":"CVSS:4.0/AV:L/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:P/AU:Y/R:U/V:C/RE:L/U:Amber"}}],"source":{"discovery":"UNKNOWN"},"x_generator":{"engine":"Vulnogram 1.0.2"}},"adp":[{"metrics":[{"other":{"type":"ssvc","content":{"timestamp":"2026-07-01T15:07:18.915117Z","id":"CVE-2026-12374","options":[{"Exploitation":"none"},{"Automatable":"no"},{"Technical Impact":"total"}],"role":"CISA Coordinator","version":"2.0.3"}}}],"title":"CISA ADP Vulnrichment","providerMetadata":{"orgId":"134c704f-9b21-4f2e-91b3-4a467353bcc0","shortName":"CISA-ADP","dateUpdated":"2026-07-01T15:07:24.153Z"}}]}}