Authentication Bypass in Check Point Security Management Server
Summary
| CVE | CVE-2026-18574 |
|---|---|
| State | PUBLISHED |
| Assigner | checkpoint |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-08-03 13:17:13 UTC |
| Updated | 2026-08-03 17:40:27 UTC |
| Description | An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system. Check Point discovered this issue internally and has no indication of active exploitation. |
Risk And Classification
Primary CVSS: v4.0 9.3 CRITICAL from [email protected]
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Problem Types: CWE-288 | CWE-288 CWE-288: Authentication Bypass Using an Alternate Path or Channel
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 4.0 | [email protected] | Secondary | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/C... |
| 4.0 | CNA | CVSS | 9.3 | CRITICAL | CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
CVSS v4.0 Breakdown
Attack Vector
NetworkAttack Complexity
LowAttack Requirements
NonePrivileges Required
NoneUser Interaction
NoneConfidentiality
HighIntegrity
HighAvailability
HighSub Conf.
NoneSub Integrity
NoneSub Availability
NoneCVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Checkpoint | Security Management Server | affected R82.10 with Jumbo Hotfix Accumulator Take 39 or below | Not specified |
| CNA | Checkpoint | Security Management Server | affected R82 with Jumbo Hotfix Accumulator Take 121 or below | Not specified |
| CNA | Checkpoint | Security Management Server | affected R81.20 with Jumbo Hotfix Accumulator Take 160 or below | Not specified |
| CNA | Checkpoint | Security Management Server | affected R81.10 | Not specified |
| CNA | Checkpoint | Security Management Server | affected R81 | Not specified |
| CNA | Checkpoint | Security Management Server | affected R80.40 | Not specified |
| CNA | Checkpoint | Security Management Server | affected R80.30 | Not specified |
| CNA | Checkpoint | Security Management Server | affected R80.20 | Not specified |
| CNA | Checkpoint | Security Management Server | affected R80.10 | Not specified |
| CNA | Checkpoint | Security Management Server | affected R80 | Not specified |
| CNA | Checkpoint | Multi-Domain Security Management Server | affected R82.10 with Jumbo Hotfix Accumulator Take 39 or below | Not specified |
| CNA | Checkpoint | Multi-Domain Security Management Server | affected R82 with Jumbo Hotfix Accumulator Take 121 or below | Not specified |
| CNA | Checkpoint | Multi-Domain Security Management Server | affected R81.20 with Jumbo Hotfix Accumulator Take 160 or below | Not specified |
| CNA | Checkpoint | Multi-Domain Security Management Server | affected R81.10 | Not specified |
| CNA | Checkpoint | Multi-Domain Security Management Server | affected R81 | Not specified |
| CNA | Checkpoint | Multi-Domain Security Management Server | affected R80.40 | Not specified |
| CNA | Checkpoint | Multi-Domain Security Management Server | affected R80.30 | Not specified |
| CNA | Checkpoint | Multi-Domain Security Management Server | affected R80.20 | Not specified |
| CNA | Checkpoint | Multi-Domain Security Management Server | affected R80.10 | Not specified |
| CNA | Checkpoint | Multi-Domain Security Management Server | affected R80 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| support.checkpoint.com/results/sk/sk185222 | [email protected] | support.checkpoint.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.