Description
An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.
Published: 2026-07-22
Score: 9.1 Critical
EPSS: 20.6% Moderate
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

An authentication bypass flaw in Check Point’s Security Management and Multi‑Domain Security Management lets an unauthenticated attacker run administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a misconfigured Trusted Client list.

Affected Systems

Check Point Multi‑Domain Security Management and Quantum Security Management are affected. No specific version information is provided in the advisory, so all instances of these products are considered at risk until patched.

Risk and Exploitability

The CVSS score of 9.1 indicates critical severity and the attack vector is remote over a network. Exploitation requires that the attacker can reach the Management Server without firewall protection or with a misconfigured Trusted Client list. The EPSS score of 21% indicates a high probability of exploitation. The vulnerability is not listed in CISA’s KEV catalog, but the lack of protective controls can still render the system highly susceptible. If exposed to the public internet or an untrusted network, the exploit can be readily performed, resulting in administrative control.

Generated by OpenCVE AI on August 3, 2026 at 23:37 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the newest Check Point patch that addresses the authentication bypass in Security Management and Multi‑Domain Security Management.
  • Configure the Management Server to accept connections only from Trusted Clients and block all other IP addresses.
  • Ensure the Management Server is protected by a firewall that restricts inbound access to the required internal network only and monitors for unusual authentication activity.

Generated by OpenCVE AI on August 3, 2026 at 23:37 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Checkpoint
Checkpoint multi-domain Management
Checkpoint quantum Security Management
Vendors & Products Checkpoint
Checkpoint multi-domain Management
Checkpoint quantum Security Management

Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.
Title Management Authentication Bypass and Privilege Escalation
Weaknesses CWE-287
References

Subscriptions

Checkpoint Multi-domain Management Quantum Security Management
cve-icon MITRE

Status: PUBLISHED

Assigner: checkpoint

Published:

Updated: 2026-07-24T03:56:14.016Z

Reserved: 2026-07-13T10:24:07.648Z

Link: CVE-2026-62144

cve-icon Vulnrichment

Updated: 2026-07-22T19:30:10.402Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-22T14:17:22.807

Modified: 2026-07-24T05:16:45.793

Link: CVE-2026-62144

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-03T23:45:06Z

Weaknesses