Description
An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter communication port and bypass CatchPulse's security policy enforcement.
Published: 2026-08-06
Score: 8.4 High
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

The vulnerability is an improper access control flaw that allows a non‑administrative local user to connect to an unrestricted kernel filter communication port in CatchPulse. By doing so the attacker can bypass the software’s security policy enforcement, effectively elevating privileges and accessing protected resources. This flaw directly exposes system integrity and availability to unauthorized manipulation.

Affected Systems

SecureAge’s CatchPulse application is affected. No specific product versions were listed in the advisory, so all deployed versions prior to the patch are potentially vulnerable.

Risk and Exploitability

The CVSS score of 8.4 indicates a high‑severity risk and the omission of an EPSS score means we cannot quantify current exploitation probability. The vulnerability is not listed in the CISA KEV catalog, suggesting no publicly known exploits yet. The attack vector is inferred to be local, requiring a non‑administrative user with access to the host, or an attacker who can execute code locally. Given the direct connection to a kernel‑level communication channel, a successful exploitation would allow the attacker to bypass high‑level security controls and potentially modify system behavior.

Generated by OpenCVE AI on August 6, 2026 at 11:21 UTC.

Remediation

Vendor Solution

Users and administrators of affected products are advised to update to the latest versions.


OpenCVE Recommended Actions

  • Update CatchPulse to the latest patch version released by SecureAge.
  • Restrict or disable access to the kernel filter communication port for non‑authenticated users.
  • Configure system firewall rules to block unauthorized connections to the port.
  • Audit local user accounts to ensure only trusted administrators have elevated privileges.

Generated by OpenCVE AI on August 6, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Secureage
Secureage catchpulse
Weaknesses CWE-284
Vendors & Products Secureage
Secureage catchpulse

Thu, 06 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description An improper access control vulnerability in CatchPulse could allow a non-administrative local attacker to connect to an unrestricted kernel filter communication port and bypass CatchPulse's security policy enforcement.
Title Improper access control vulnerability in CatchPulse
References
Metrics cvssV3_1

{'score': 8.4, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:N/I:H/A:H'}


Subscriptions

Secureage Catchpulse
cve-icon MITRE

Status: PUBLISHED

Assigner: CSA

Published:

Updated: 2026-08-06T09:18:32.685Z

Reserved: 2026-06-18T04:11:38.685Z

Link: CVE-2026-55978

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T11:30:02Z

Weaknesses