An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.
History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Checkpoint
Checkpoint multi-domain Management
Checkpoint quantum Security Management
Vendors & Products Checkpoint
Checkpoint multi-domain Management
Checkpoint quantum Security Management

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.
Title Management Authentication Bypass and Privilege Escalation
Weaknesses CWE-287
References

cve-icon MITRE

Status: PUBLISHED

Assigner: checkpoint

Published: 2026-07-22T13:53:35.969Z

Updated: 2026-07-24T03:56:14.016Z

Reserved: 2026-07-13T10:24:07.648Z

Link: CVE-2026-62144

cve-icon Vulnrichment

Updated: 2026-07-22T19:30:10.402Z

cve-icon NVD

No data.

cve-icon Redhat

No data.