sk185153 - CVE-2026-62145 - Local privilege escalation in Gaia Portal
CVE-2026-62145 - Local privilege escalation in Gaia Portal
Please read this important update from Check Point.
Security Alert:
High
Product
Security Gateways, Security Management
Version
R77.30 (EOS), R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
OS
Gaia
Last Modified
2026-07-22
Symptoms
- A vulnerability in Gaia Portal allows an authenticated attacker with read-only access to run commands as root.
- Affected Products and Versions:
- Versions: R77.30, R80, R80.10, R80.20, R80.30, R81 R81.10, R81.20, R82, R82.10
- Products: Security Gateway, Security Management
Note: Check Point Spark Gateways are not affected
- This issue received the ID CVE-2026-62145.
Mitigation
- Follow Check Point Gateway and Management Hardening Best Practices Guide recommendation to restrict the IP address of Gaia OS admin access to only allowed and trusted hosts/subnets.
Additionally, enable MFA (Multi-Factor Authentication) for administrators. - In Gaia Portal > System Management > Host Access > add only trusted hosts/subnets in Allowed Hosts
For more info about Host Access, refer to the Gaia Administration Guide. 3. In Gaia Portal > User Management > Authentication > click on Enable Two-Factor Authentication
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 36
- Jumbo Hotfix Accumulator for R82 starting from Take 118
- Jumbo Hotfix Accumulator for R81.20 starting from Take 158
Article Properties
Access Level: General
Severity: High
Status: Approved
Date Created: 2026-07-14
Last Modified: 2026-07-22