[CVE-2026-55979] Named Pipe NULL DACL

CVE ID

CVE-2026-55979 | 5.2 (Medium)

An improper access control check in CatchPulse’s named pipe communication interface could allow an attacker to invoke CatchPulse functions. It is limited to operations that enforce more restrictive security policies.

Affected & Fixed Versions
Product Vulnerable Version Fixed Version Status

CatchPulse 

10.10.0 and earlier
10.10.1

✓Resolved

Recommended Action

Users and administrators of affected products are advised to update to the latest versions.

Acknowledgement

SecureAge thanks Ms Ang Kar Min for responsibly disclosing this issue through coordinated vulnerability disclosure.

Advisory Details
Status

✓ Resolved

Severity

Medium

Product

CatchPulse

Platform

Windows

Attack Type

Local