Authentication Bypass Vulnerability in Check Point Security Management
CVE-2026-62144

9.1CRITICAL

What is CVE-2026-62144?

CVE-2026-62144 is an authentication bypass vulnerability affecting Check Point Security Management and Multi-Domain Security Management systems. This product is crucial for organizations as it provides centralized security policy management, allowing the enforcement of security measures across various network elements. The vulnerability enables an unauthenticated remote attacker to execute administrative commands on the Management Server. Additionally, if exploited, it may allow the attacker to execute commands on managed Security Gateways, posing a significant risk to network integrity and confidentiality. Exploitation requires network access to the Management Server without adequate firewall protection or through configurations that overlook restrictions for Trusted Clients, highlighting potential lapses in security postures that could be manipulated by attackers.

Potential impact of CVE-2026-62144

  1. Unauthorized Command Execution: Attackers could execute high-level administrative commands on the Management Server, leading to unauthorized access and control over critical security configurations.

  2. Compromise of Security Gateways: The ability to execute commands on managed Security Gateways could result in a broader compromise, potentially exposing sensitive data and allowing attackers to manipulate traffic and security policies.

  3. Increased Risk of Data Breaches: The vulnerability creates pathways for attackers to breach the organization’s defenses, potentially leading to data loss, theft, and violations of regulatory compliance standards due to the manipulation or exfiltration of sensitive data.

Affected Version(s)

Multi-Domain Security Management R82.10 with Jumbo Hotfix Take 36 or below

Multi-Domain Security Management R82 with Jumbo Hotfix Take 118 or below

Multi-Domain Security Management R81.20 with Jumbo Hotfix Take 158 or below

References

EPSS Score

20% chance of being exploited in the next 30 days.

CVSS V3.1

Score:
9.1
Severity:
CRITICAL
Confidentiality:
High
Integrity:
High
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.