CVE-2026-15710
Last modified
CVE-2026-15710 is a medium-severity vulnerability rated 6.8/10 on the CVSS scale. An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the kernel driver to the daemon lacked proper token-based message validation, allowing local unprivileged processes to send unauthorized queries. EPSS estimates a 0.10% chance of exploitation in the next 30 days.
Description
An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the kernel driver to the daemon lacked proper token-based message validation, allowing local unprivileged processes to send unauthorized queries. Additionally, a reply buffer used by the port message handler was not properly initialized before returning data, leaking residual kernel pool memory from prior allocations. A local unprivileged attacker could exploit this vulnerability to enumerate DLP configuration and feature flags, extract live session tokens, and read kernel memory fragments from other users' operations.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| Netskope | Endpoint DLP | < R141 |
References
Timeline
- Published
- Last Modified
- Status
- Awaiting Analysis
Frequently Asked Questions
What is CVE-2026-15710?
How severe is CVE-2026-15710?
How do I fix CVE-2026-15710?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-15702A security vulnerability has been detected in tamagui up to …6.3
- CVE-2026-15703A vulnerability was detected in SourceCodester Simple and Ni…7.3
- CVE-2026-15704In Eclipse BaSyx Go Components versions up to and including …9.8
- CVE-2026-15706Missing authentication for critical function vulnerability i…9.8
- CVE-2026-15709A flaw was found in libsoup's WebSocket implementation when …7.5
- CVE-2026-1571User-controlled input is reflected into the HTML output with…6.1
- CVE-2026-15711A vulnerability was found in libsoup's WebSocket frame parsi…7.5
- CVE-2026-15712A heap buffer over-read vulnerability was discovered in libs…5.9
- CVE-2026-15713A vulnerability was found in libsoup's HTTP/2 protocol imple…5.9
- CVE-2026-15714An out-of-bounds read vulnerability was found in libsoup's m…6.5
- CVE-2026-15715A vulnerability was identified in SourceCodester Class and E…4.3
- CVE-2026-15718We are aware that exploit code for this is public however we…4.3
Are you affected by CVE-2026-15710?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
