CVE-2026-62144 PUBLISHED

Management Authentication Bypass and Privilege Escalation

Assigner: checkpoint
Reserved: 13.07.2026 Published: 22.07.2026 Updated: 22.07.2026

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.

Product Status

Vendor checkpoint
Product Quantum Security Management
Versions
  • Version R82.10 with Jumbo Hotfix Take 36 or below is affected
  • Version R82 with Jumbo Hotfix Take 118 or below is affected
  • Version R81.20 with Jumbo Hotfix Take 158 or below is affected
  • Version R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30 is affected
Vendor checkpoint
Product Multi-Domain Security Management
Versions
  • Version R82.10 with Jumbo Hotfix Take 36 or below is affected
  • Version R82 with Jumbo Hotfix Take 118 or below is affected
  • Version R81.20 with Jumbo Hotfix Take 158 or below is affected
  • Version R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30 is affected

References

Problem Types

  • CWE-287: Improper Authentication. CWE