SB2026080387 - Authentication bypass in Check Point Gaia



SB2026080387 - Authentication bypass in Check Point Gaia

Published: August 3, 2026

Security Bulletin ID SB2026080387
CSH Severity
High
Patch available
YES
Number of vulnerabilities 1
Exploitation vector Remote access
Highest impact Code execution

Breakdown by Severity

High 100%
  • Low
  • Medium
  • High
  • Critical

Description

This security bulletin contains information about 1 vulnerability.


1) Improper authentication (CVE-ID: CVE-2026-18574)

CWE-ID: CWE-287 - Improper Authentication

CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]


The vulnerability allows a remote attacker to execute arbitrary commands.

The vulnerability exists due to improper authentication in management authentication on the Security Management Server when handling management access requests. A remote attacker can bypass authentication to execute arbitrary commands.

Successful exploitation requires network access to the Security Management Server. Environments that do not restrict Trusted Clients or that expose Management services to untrusted networks may have increased exposure.


Remediation

Install update from vendor's website.