Management Authentication Bypass and Privilege Escalation
Summary
| CVE | CVE-2026-62144 |
|---|---|
| State | PUBLISHED |
| Assigner | checkpoint |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2026-07-22 14:17:22 UTC |
| Updated | 2026-07-22 20:51:14 UTC |
| Description | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients. |
Risk And Classification
Primary CVSS: v3.1 9.1 CRITICAL from ADP
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Problem Types: CWE-287 | CWE-287 CWE-287: Improper Authentication.
| Version | Source | Type | Score | Severity | Vector |
|---|---|---|---|---|---|
| 3.1 | ADP | DECLARED | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
| 3.1 | 134c704f-9b21-4f2e-91b3-4a467353bcc0 | Secondary | 9.1 | CRITICAL | CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
CVSS v3.1 Breakdown
Attack Vector
NetworkAttack Complexity
LowPrivileges Required
NoneUser Interaction
NoneScope
UnchangedConfidentiality
HighIntegrity
HighAvailability
NoneCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Vendor Declared Affected Products
| Source | Vendor | Product | Version | Platforms |
|---|---|---|---|---|
| CNA | Checkpoint | Quantum Security Management | affected R82.10 with Jumbo Hotfix Take 36 or below | Not specified |
| CNA | Checkpoint | Quantum Security Management | affected R82 with Jumbo Hotfix Take 118 or below | Not specified |
| CNA | Checkpoint | Quantum Security Management | affected R81.20 with Jumbo Hotfix Take 158 or below | Not specified |
| CNA | Checkpoint | Quantum Security Management | affected R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30 | Not specified |
| CNA | Checkpoint | Multi-Domain Security Management | affected R82.10 with Jumbo Hotfix Take 36 or below | Not specified |
| CNA | Checkpoint | Multi-Domain Security Management | affected R82 with Jumbo Hotfix Take 118 or below | Not specified |
| CNA | Checkpoint | Multi-Domain Security Management | affected R81.20 with Jumbo Hotfix Take 158 or below | Not specified |
| CNA | Checkpoint | Multi-Domain Security Management | affected R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30 | Not specified |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| support.checkpoint.com/results/sk/sk185152 | [email protected] | support.checkpoint.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.