Description
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Published: 2026-06-08
Score: n/a
EPSS: n/a
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A logic flow weakness in the certificate validation path for the deprecated IKEv1 key exchange allows an unauthenticated attacker to bypass user authentication on a remote VPN connection. The flaw enables the attacker to establish a link to the gateway without possessing a valid user password, thereby granting unauthorized access to the protected network and all resources behind the gateway. This vulnerability falls under CWE‑287 (Authentication Bypass by Missing or Incorrect Authentication).

Affected Systems

The flaw affects Check Point’s Quantum Security Gateway and Spark Firewalls. No specific product versions are listed in the advisory, so all deployments of these gateway releases that use the affected IKEv1 logic are potentially vulnerable.

Risk and Exploitability

The EPSS score is not available, and the vulnerability is not listed in CISA’s KEV catalog. The CVSS score is absent, but the nature of the flaw—unauthenticated remote bypass—indicates a high severity. Because the attack requires only network connectivity to the VPN service and the construction of a certificate that triggers the logic flaw, the exploitability is likely high if the gateway is exposed to untrusted traffic. Attackers would benefit from network access that can reach the VPN interface; no special system or user privileges are required. The lack of publicly disclosed exploits means the current risk is primarily from the theoretical possibility of exploitation, but the potential for widespread credentialless access makes it urgent for administrators to verify mitigation posture.

Generated by OpenCVE AI on June 8, 2026 at 12:21 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Check the vendor support portal for a firmware or software patch that addresses the authentication bypass issue and apply it as soon as it becomes available.
  • Disable the deprecated IKEv1 key exchange protocol on all VPN endpoints to eliminate the execution path that the flaw exploits.
  • Enforce stronger authentication mechanisms, such as multifactor authentication, and validate server certificates rigorously; consider upgrading to IKEv2 or alternative VPN protocols that do not rely on the vulnerable logic.
  • Continuously monitor VPN logs for unexpected or repeated connection attempts and isolate any endpoints that exhibit suspicious activity promptly.

Generated by OpenCVE AI on June 8, 2026 at 12:21 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 08 Jun 2026 11:45:00 +0000

Type Values Removed Values Added
Description A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Title User Authentication Bypass in VPN Remote Access and Mobile Access
Weaknesses CWE-287
References

Subscriptions

No data.

cve-icon MITRE

Status: PUBLISHED

Assigner: checkpoint

Published:

Updated: 2026-06-08T11:07:15.746Z

Reserved: 2026-06-07T09:42:08.251Z

Link: CVE-2026-50751

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-08T12:16:32.367

Modified: 2026-06-08T12:16:32.367

Link: CVE-2026-50751

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-08T12:30:23Z

Weaknesses