Improper authentication in Gaia - CVE-2026-18574

 

Improper authentication in Gaia - CVE-2026-18574

Published: August 3, 2026


Vulnerability identifier: #VU140806
CSH Severity: High
CVSS v4: 9.3 [CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2026-18574
CWE-ID: CWE-287
Exploitation vector: Remote access
Exploit availability: No public exploit available

Vulnerability details

The vulnerability allows a remote attacker to execute arbitrary commands.

The vulnerability exists due to improper authentication in management authentication on the Security Management Server when handling management access requests. A remote attacker can bypass authentication to execute arbitrary commands.

Successful exploitation requires network access to the Security Management Server. Environments that do not restrict Trusted Clients or that expose Management services to untrusted networks may have increased exposure.


Affected software

Gaia

How to mitigate CVE-2026-18574

Install security update from vendor's website.

Gaia - addressed in versions R81.20 Take 161, R82.10 Take 40, R82 Take 122

External References

Related Security Bulletins