SB2026080387 - Authentication bypass in Check Point Gaia
Published: August 3, 2026
Breakdown by Severity
- Low
- Medium
- High
- Critical
Description
This security bulletin contains information about 1 vulnerability.
1) Improper authentication (CVE-ID: CVE-2026-18574)
CWE-ID: CWE-287 - Improper Authentication
CVSSv4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
The vulnerability allows a remote attacker to execute arbitrary commands.
The vulnerability exists due to improper authentication in management authentication on the Security Management Server when handling management access requests. A remote attacker can bypass authentication to execute arbitrary commands.
Successful exploitation requires network access to the Security Management Server. Environments that do not restrict Trusted Clients or that expose Management services to untrusted networks may have increased exposure.
Remediation
Install update from vendor's website.