sk185152 - CVE-2026-62144 - Management Authentication Bypass and Privilege Escalation
CVE-2026-62144 - Management Authentication Bypass and Privilege Escalation
Please read this important update from Check Point.
Security Alert:
High
Product
Multi-Domain Security Management, Security Management
Version
R77.30 (EOS), R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
Last Modified
2026-07-22
Symptoms
Impact: An unauthenticated attacker can run any command on the Management including run-script and exec-command on Security Gateway (Check Point Firewall).
Affected Products and versions:
- Products: Security Management, Multi-Domain Security Management Server (MDS)
- Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81 R81.10, R81.20, R82, R82.10
Conditions: Successful exploit requires management access without Firewall protection OR no restrictions on Trusted Clients (GUI clients).
This issue received the ID CVE-2026-62144.
Mitigation
Follow the Check Point Hardening Best Practices Guide.
Limit Trusted Clients (GUI clients) to trusted IP addresses/subnets.
To do so,
- In SmartConsole, go to Manage & Settings > Permissions & Administrators > Trusted Clients.
- Double-click the client you want to edit.
- In the Trusted Client configuration window that opens, change the settings as needed.
- Make sure do not use "Any" as a Type.
- Click OK.
Protect Management access with Firewall, restrict access to trusted IP addresses, and verify that implied rules for control connections are enabled. This will create an implied rule that will prevent management access for non-authorized IP addresses.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 36
- Jumbo Hotfix Accumulator for R82 starting from Take 118
- Jumbo Hotfix Accumulator for R81.20 starting from Take 158
Article Properties
- Access Level: General
- Severity: High
- Status: Approved
- Date Created: 2026-07-14
- Last Modified: 2026-07-22