Description
An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions. This is limited to operations that enforce more restrictive security policies.
Published: 2026-08-06
Score: 5.2 Medium
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An improper access control check in CatchPulse’s named pipe communication interface allows an attacker to invoke CatchPulse functions that are normally protected by stricter security policies. The flaw effectively bypasses the intended privilege enforcement, enabling authorized actions to be executed by users or processes that should not have such permissions. The impact is a loss of confidentiality and integrity of the data processed by the restricted functions, as well as potential escalation of privileges for the attacker.

Affected Systems

The vulnerability affects SecureAge’s CatchPulse product. No specific version information is provided in the advisory, so any installation that includes the named pipe communication interface may be susceptible. The flaw resides in the inter‑process communication layer used by CatchPulse to receive commands from external clients.

Risk and Exploitability

The CVSS score of 5.2 classifies the vulnerability as moderate in severity. Attackers would need to target the named pipe, which typically involves local or same‑host access; the exact attack vector is not explicitly stated in the advisory, so it is inferred to be local. Because the EPSS score is not available, the likelihood of exploitation is unknown, and the vulnerability is not listed in the CISA KEV catalog. Nonetheless, the ability to invoke protected functions without proper authorization justifies a prompt patch.

Generated by OpenCVE AI on August 6, 2026 at 11:21 UTC.

Remediation

Vendor Solution

Users and administrators of affected products are advised to update to the latest versions.


OpenCVE Recommended Actions

  • Apply the vendor’s latest patch or upgrade CatchPulse to the most recent version as recommended by SecureAge.
  • If an immediate patch is unavailable, restrict access to the named pipe by setting file permissions so that only trusted system accounts can connect.
  • Disable or remove unused named pipe communication functions and replace them with protected APIs that enforce proper access control.

Generated by OpenCVE AI on August 6, 2026 at 11:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 06 Aug 2026 11:45:00 +0000

Type Values Removed Values Added
First Time appeared Secureage
Secureage catchpulse
Weaknesses CWE-284
Vendors & Products Secureage
Secureage catchpulse

Thu, 06 Aug 2026 10:15:00 +0000

Type Values Removed Values Added
Description An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions. This is limited to operations that enforce more restrictive security policies.
Title Improper access control check in CatchPulse's named pipe communication interface
References
Metrics cvssV3_1

{'score': 5.2, 'vector': 'CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L'}


Subscriptions

Secureage Catchpulse
cve-icon MITRE

Status: PUBLISHED

Assigner: CSA

Published:

Updated: 2026-08-06T09:20:55.849Z

Reserved: 2026-06-18T04:11:38.685Z

Link: CVE-2026-55979

cve-icon Vulnrichment

No data.

cve-icon NVD

No data.

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-06T11:30:02Z

Weaknesses