# CVE-2026-62145 - Local privilege escalation in Gaia Portal

Please read this important update from Check Point.

Security Alert:

**High**

## Product
**Security Gateways, Security Management**

## Version
**R77.30 (EOS), R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10**

## OS
**Gaia**

## Last Modified
**2026-07-22**

## Symptoms

- A vulnerability in Gaia Portal allows an authenticated attacker with read-only access to run commands as root.
- **Affected Products and Versions:**
  - Versions: R77.30, R80, R80.10, R80.20, R80.30, R81 R81.10, R81.20, R82, R82.10
  - Products: Security Gateway, Security Management  
    Note: Check Point Spark Gateways are not affected
- This issue received the ID [CVE-2026-62145](https://www.cve.org/CVERecord?id=CVE-2026-62145).

### Mitigation

1. Follow [Check Point Gateway and Management Hardening Best Practices Guide](https://sc1.checkpoint.com/documents/Check_Point_Gateway_and_Management_Hardening/CP_Check_Point_Gateway_and_Management_Hardening.pdf) recommendation to restrict the IP address of Gaia OS admin access to only allowed and trusted hosts/subnets.  
   Additionally, enable MFA (Multi-Factor Authentication) for administrators.
2. In **Gaia Portal** > **System Management** > **Host Access** > add only trusted hosts/subnets in **Allowed Hosts**

****  
   For more info about Host Access, refer to the [Gaia Administration Guide](https://sc1.checkpoint.com/documents/R82.10/WebAdminGuides/EN/CP_R82.10_Gaia_AdminGuide/Content/Topics-GAG/Host-Access.htm).
3. In **Gaia Portal** > **User Management** > **Authentication** > click on **Enable Two-Factor Authentication**  
     
   ****

## Solution

This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 36
- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 118
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 158

## Article Properties
**Access Level:** General  
**Severity:** High  
**Status:** Approved  
**Date Created:** 2026-07-14  
**Last Modified:** 2026-07-22
