Improper authentication in Gaia - CVE-2026-50751
Published: June 9, 2026 / Updated: August 31, 2026
Vulnerability details
The vulnerability allows a remote attacker to bypass authentication process.
The vulnerability exists due to a logic error in the Remote Access and Mobile Access certificate validation during deprecated IKEv1 key exchange. A remote attacker can establish a remote access VPN connection without a valid user password and gain access to network resources available to authenticated users.
Note, the vulnerability is being actively exploited in the wild.
Affected software
How to mitigate CVE-2026-50751
Links to Public Exploits and PoC-codes
- Exploit #13010 - CVE-2026-50751---Check-Point-IKEv1-Authentication-Bypass-Exploit (PoC de CVE-2026-50751: bypass de autenticacion IKEv1 en Check Point Remote/Mobile Access.) (August 31, 2026)
- Exploit #12993 - Project-CVE-2026-50751 (IKEv1 VPN scanners, attempts a Check Point authentication-bypass exploit, and includes internal network scanning and reverse-shell features. ) (August 31, 2026)