VulnerabilityDeferred
CVE-2026-55979
An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions.
MEDIUM 5.2EPSS 0.09%
Does this matter?
Lower severity and a low EPSS score (0.09%). Track it; it rarely justifies an emergency change on its own.
Description
An improper access control check in CatchPulse's named pipe communication interface could allow an attacker to invoke CatchPulse functions. This is limited to operations that enforce more restrictive security policies.
- CVSS 3.1
- 5.2 MEDIUMCVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:L/I:N/A:L
- EPSS
- 0.09% probability · 1th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-284
- Source
- 5f57b9bf-260d-4433-bf07-b6a79e9bb7d4
References
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.