Description
A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
Published: 2026-07-22
Score: 7.5 High
EPSS: 7.5% Low
KEV: No
Impact: n/a
Action: n/a
AI Analysis

Impact

A flaw in the Check Point Gaia Portal allows an authenticated user with only read‑only portal privileges to execute arbitrary system commands as root. The weakness is a privilege‑escalation issue (CWE‑269) and would grant an attacker full control over the gateway, enabling changes to firewall policies, installation of malware, and total compromise of the device’s protective functions.

Affected Systems

The affected products are the Check Point Quantum Security Gateway and the Check Point Quantum Security Management systems that provide the Gaia Portal. Exact firmware or release versions affected were not disclosed in the CVE data, so the vulnerability could be present in any Gaia Portal deployment until a patch or newer firmware is applied.

Risk and Exploitability

The CVSS score of 7.5 indicates a high risk to confidentiality, integrity, and availability, and the EPSS score of 8% suggests a moderate likelihood that this vulnerability will be actively exploited. The vulnerability is not listed in the CISA KEV catalog. Based on the description, the attacker must first authenticate to the Gaia Portal with a read‑only account; once logged in, no additional conditions are required for privilege escalation.

Generated by OpenCVE AI on August 4, 2026 at 15:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Check Point firmware update that fixes the Gaia Portal privilege escalation vulnerability.
  • Remove or disable any read‑only Gaia Portal accounts that are not required for normal operations.
  • Enable auditing of privileged command execution and monitor logs for suspicious activity.
  • Verify with Check Point support for any temporary workarounds if a patch is not yet available.

Generated by OpenCVE AI on August 4, 2026 at 15:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Thu, 23 Jul 2026 06:30:00 +0000

Type Values Removed Values Added
First Time appeared Checkpoint
Checkpoint quantum Security Gateway
Checkpoint quantum Security Management
Vendors & Products Checkpoint
Checkpoint quantum Security Gateway
Checkpoint quantum Security Management

Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
Title Local Privilege Escalation in Gaia Portal
Weaknesses CWE-269
References
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:H/PR:L/UI:N/S:U/C:H/I:H/A:H'}


Subscriptions

Checkpoint Quantum Security Gateway Quantum Security Management
cve-icon MITRE

Status: PUBLISHED

Assigner: checkpoint

Published:

Updated: 2026-07-24T03:56:05.075Z

Reserved: 2026-07-13T10:24:07.648Z

Link: CVE-2026-62145

cve-icon Vulnrichment

Updated: 2026-07-22T18:59:12.775Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2026-07-22T14:17:22.920

Modified: 2026-07-24T05:16:45.940

Link: CVE-2026-62145

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-04T15:45:03Z

Weaknesses
  • CWE-269

    Improper Privilege Management