CVEReports
CVEReports

Automated vulnerability intelligence platform. Comprehensive reports for high-severity CVEs generated by AI.

Product

  • Home
  • Sitemap
  • RSS Feed

Company

  • About
  • Contact
  • Privacy Policy
  • Terms of Service

© 2026 CVEReports. All rights reserved.

Made with love by Amit Schendel & Alon Barad



CVE-2026-18574

CVE-2026-18574: Authentication Bypass via Alternate Path in Check Point Security Management Server

Amit Schendel
Amit Schendel
Senior Security Researcher

Aug 4, 2026·6 min read·129 visits

Executive Summary (TL;DR)

Unauthenticated remote command execution on Check Point Security Management Servers via alternate path authentication bypass (CWE-288), CVSS 9.3.

A critical authentication bypass vulnerability (CVE-2026-18574) in Check Point Security Management and Multi-Domain Security Management (MDS) Servers allows unauthenticated remote attackers to execute arbitrary system commands with administrative privileges. The flaw stems from an alternate path authentication bypass (CWE-288) in the management interface daemons.

Vulnerability Overview

CVE-2026-18574 is an administrative authentication bypass vulnerability located in the core management plane of the Check Point Security Management Server and Multi-Domain Security Management Server (MDS). The flaw lies specifically in the handling of external requests directed to secondary administrative interfaces. A remote, unauthenticated attacker can exploit this vulnerability to bypass primary authentication layers and access system-level functions.

The Security Management Server acts as the centralized console for managing security policies, configurations, and logs for all distributed Check Point gateways across an organization. This system exposes several listening ports, including TCP 18190 for the Check Point Management Interface (CPMI) and TCP 443/19009 for Web API and Check Point Management Daemon (CPM) services. These exposed ports constitute a highly privileged attack surface that must remain secured against unauthorized interaction.

Under CWE-288, this vulnerability allows access via an alternate path or channel. Standard authentication routines are executed when clients attempt to connect using official APIs or SmartConsole workflows. However, specific administrative endpoints fail to enforce these validation routines, allowing direct routing of unauthenticated requests to the backend execution context.

Root Cause Analysis (CWE-288)

The root cause of CVE-2026-18574 resides in the divergence of authentication verification paths within the Security Management Server architecture. While the central Java-based management daemon (CPM) implements robust Java Authentication and Authorization Service (JAAS) filters for standard API calls, certain proprietary sub-protocols do not share these filters. Specifically, requests routed through alternative administrative channels bypass the mandatory authentication filter pipeline entirely.

When an administrative request is received on the CPMI or Web API services, the server determines the target internal handler based on URL routing or protocol message headers. Due to a logical error in the routing dispatcher, messages targeting a subset of administrative handlers are forwarded directly without validating the presence of a valid session token. The backend service accepts these unauthenticated requests as implicitly trusted because they originate from an internal routing context.

This trust model failure allows the unauthenticated request to reach execution blocks that require administrative privilege. Because the handlers execute commands directly on the underlying secure Linux operating system, the lack of input verification and session validation translates directly into arbitrary command execution. The system processes the crafted input under the context of the running daemon, which possesses root-level permissions.

Architectural Data Flow and Flaw

To understand how the vulnerability manifests, we must analyze the data flow of incoming administrative requests. Standard operations undergo session token evaluation, credential checking, and access control list (ACL) mapping. The alternate path bypasses these checkpoints, directly linking the network input layer with the backend system command executor.

The following flow diagram illustrates the difference between the validated standard administrative path and the vulnerable alternate path:

The diagram shows that the standard path forces credential validation before routing requests to the command execution context. The alternate path skips this verification, allowing raw inputs to reach the command execution engine directly. This architecture lacks defense-in-depth, as the backend execution engines rely entirely on the outer perimeter filters for security enforcement.

Exploitation Methodology & Prerequisites

Exploiting CVE-2026-18574 does not require pre-existing user accounts or cryptographic materials. The attacker only requires direct network visibility to the target Check Point Security Management Server on management ports such as TCP 18190 or TCP 443. This makes the vulnerability highly critical for instances exposed to untrusted internal subnets or the public internet.

The exploitation sequence starts with the generation of a malformed management protocol payload. The attacker transmits this payload to one of the exposed management ports. The payload targets the unauthenticated routing path, specifying a target administrative utility and embedding the desired system-level command arguments within the message body.

Upon processing the request, the management server executes the embedded system commands without verifying credentials. The attacker receives confirmation of execution via the network response or through out-of-band communication established by the executed commands. There is currently no public proof-of-concept exploit code or evidence of active exploitation in the wild, which limits immediate risk to environments with restricted management access.

Impact and Post-Exploitation Consequences

A successful exploitation of CVE-2026-18574 leads to a complete compromise of the Security Management Server. Because the central management services run with root-level operating system privileges, the injected commands execute with maximum capability. This grants the attacker full read, write, and delete permissions over the operating system, including the ability to deploy permanent administrative backdoors.

The primary concern is the subsequent system impact on connected enforcement gateways. The compromised management server holds the security policies, configuration files, and cryptographic keys for all managed security gateways across the enterprise network. An attacker can use this access to push modified security policies that permit malicious traffic, disable logging, or download malicious payloads to the entire gateway fleet.

Furthermore, the management database contains password hashes, VPN pre-shared keys, and API keys used for third-party integrations. Attackers can harvest these credentials to move laterally within the network. This converts a localized server compromise into a broad infrastructure compromise.

Remediation and Network Hardening

The primary remediation strategy is the installation of the official Check Point Jumbo Hotfix Accumulator (HFA) takes. Organizations must update R82.10 deployments to Take 40 or higher, R82 deployments to Take 122 or higher, and R81.20 deployments to Take 161 or higher. Legacy installations running R81.10, R81, or R80.x have reached End of Support and must be upgraded to a supported release prior to hotfix application.

For environments where immediate software updates are impossible, network-level workarounds must be applied immediately. Administrators should restrict GUI client connections using the Trusted Clients feature in SmartConsole. This configuration limits connections to authorized IP addresses and subnets, blocking requests from unauthorized origins before they can reach the vulnerable routing logic.

Additionally, strict firewall access control lists must protect the management server. Ports TCP 18190, 443, and 19009 must be restricted strictly to trusted management subnets. Exposing these administrative services to the public internet or open enterprise subnets must be strictly prohibited to prevent unauthorized access.

Technical Appendix

CVSS Score
9.3/ 10
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

Affected Systems

Check Point Security Management ServerCheck Point Multi-Domain Security Management Server (MDS)

Affected Versions Detail

Product
Affected Versions
Fixed Version
Check Point Security Management Server / MDS
Check Point
R81.20R81.20 Jumbo HFA Take 161
Check Point Security Management Server / MDS
Check Point
R82R82 Jumbo HFA Take 122
Check Point Security Management Server / MDS
Check Point
R82.10R82.10 Jumbo HFA Take 40
AttributeDetail
CWE IDCWE-288
Attack VectorNetwork
CVSS9.3
EPSSNot assigned
ImpactArbitrary Command Execution / Full Compromise
Exploit StatusNone
KEV StatusNot Listed

MITRE ATT&CK Mapping

T1210Exploitation of Remote Services
Initial Access
T1556Modify Authentication Process
Credential Access
T1068Exploitation for Privilege Escalation
Privilege Escalation
T1059Command and Scripting Interpreter
Execution
CWE-288
Authentication Bypass Using an Alternate Path or Channel

The product implements an access control path, but it provides an alternate path or channel that does not enforce the same access controls.

Vulnerability Timeline

Initial security advisory draft sk185222 prepared internally by Check Point.
2026-08-01
CVE-2026-18574 is registered and published by the CVE Numbering Authority (Check Point).
2026-08-03
Check Point releases public advisory sk185222 detailing the authentication bypass.
2026-08-03

References & Sources

  • [1]Check Point Support Advisory sk185222
  • [2]Official CVE Record on CVE.org
  • [3]Check Point Gateway and Management Hardening Guide
  • [4]Jumbo Hotfix Accumulator for R82.10 Home Page
  • [5]Jumbo Hotfix Accumulator for R82 Home Page
  • [6]Jumbo Hotfix Accumulator for R81.20 Home Page

Attack Flow Diagram

Press enter or space to select a node. You can then use the arrow keys to move the node around. Press delete to remove it and escape to cancel.
Press enter or space to select an edge. You can then press delete to remove it or escape to cancel.

More Reports

•33 minutes ago•CVE-2026-92938
9.9

CVE-2026-92938: Remote Code Execution in vm2 via node:sqlite DatabaseSync Sandbox Escape

CVE-2026-92938 is a critical sandbox escape vulnerability in the vm2 library (versions 3.11.3 through 3.11.6) that allows arbitrary native code execution on the host when the node:sqlite built-in module is loaded inside a sandboxed NodeVM environment.

Amit Schendel
Amit Schendel
2 views•8 min read
•about 2 hours ago•CVE-2026-92937
10.0

CVE-2026-92937: Sandbox Escape leading to Remote Code Execution via Promise Indirection in vm2

CVE-2026-92937 is a critical sandbox escape vulnerability in the `vm2` Node.js library. Due to a logical failure in checking direct invocation targets inside the Proxy bridge, an attacker can register Promise callbacks using `Function.prototype.call` or `Function.prototype.apply` indirection. This bypasses the error sanitization wrappers, delivering raw host error objects directly to sandboxed callbacks and allowing the attacker to escape the sandbox and execute arbitrary shell commands on the host.

Amit Schendel
Amit Schendel
6 views•6 min read
•about 3 hours ago•CVE-2026-92935
9.5

CVE-2026-92935: Remote Code Execution via Array-Shaped Require Config in vm2 NodeVM Sandbox

CVE-2026-92935 is a critical sandbox escape and remote code execution vulnerability in the vm2 library. By supplying an array or exotic object to the require property of NodeVM while nesting is enabled, attackers can bypass security checks, load the host vm2 module, and run arbitrary shell commands on the hosting server.

Alon Barad
Alon Barad
5 views•7 min read
•about 4 hours ago•CVE-2026-92949
4.0

CVE-2026-92949: Sandbox Escape and State Mutation in vm2 via Accessor Property Descriptor Leak

CVE-2026-92949 is a sandbox bypass vulnerability in the vm2 library affecting versions 3.9.6 through 3.11.6. The flaw exists due to a breakdown in the ReadOnlyHandler proxy boundary, allowing sandboxed scripts to obtain direct references to wrapped property setters on frozen host-bound objects, ultimately leading to unauthorized state modification in the host environment. This security failure violates the read-only contract enforced by the sandbox for frozen/readonly objects, though it does not by itself allow a full execution-level realm escape. Due to systemic and structural design difficulties in securing a shared-runtime JavaScript sandbox, the vm2 library has been officially deprecated.

Amit Schendel
Amit Schendel
5 views•7 min read
•about 5 hours ago•CVE-2026-92957
9.9

CVE-2026-92957: Sandbox Escape and Remote Code Execution in vm2 via node: Prefix Policy Bypass

A vulnerability in the NodeVM component of the vm2 sandbox package through version 3.11.6 allows sandboxed code to bypass security policies restricting access to built-in modules. When a wildcard require policy is configured with negative deny entries using the 'node:' prefix (e.g., '-node:child_process'), the parser fails to recognize the exemption due to exact string comparison. As a result, the unmitigated module is registered, allowing sandboxed code to import the host child_process module and execute arbitrary system commands.

Alon Barad
Alon Barad
5 views•6 min read
•about 6 hours ago•CVE-2026-92958
8.5

CVE-2026-92958: Built-in Module Denylist Bypass via fs/promises in vm2 NodeVM Subsystem

CVE-2026-92958 is a high-severity sandbox escape and denylist bypass vulnerability within the NodeVM subsystem of the vm2 sandboxing library. When configuring wildcards with negative deny entries, exact-string matches fail to block subpaths like fs/promises. Sandboxed code can import these subpaths to bypass isolation and execute arbitrary filesystem operations on the host.

Amit Schendel
Amit Schendel
6 views•6 min read