A significant vulnerability has been identified in Check Point’s Security Management and Log Servers, which could permit attackers to execute code as root without needing login credentials. This flaw, present in the servers’ network operations, poses a critical security risk.
Details of the Vulnerability
The flaw resides within the Security Management Server, which oversees firewall policies and administrator access. According to Check Point, the vulnerability is linked to the Trusted Clients setting within the SmartConsole, which manages connections to the management server. A patch has been issued via Check Point’s LivePatch update system, and the company assures that there is no known exploitation of this vulnerability so far.
Identified as CVE-2026-91843, the flaw is rated 9.8 out of 10 on the CVSS scale, indicating its critical nature. The issue is due to a stack overflow during the login process, triggered by an overly long username in login requests, as noted by internet scanning company Censys.
Patch and Mitigation Measures
Check Point has advised that customers with automatic updates are already protected, while others should promptly apply the LivePatch fix as outlined in advisory sk1000155. The importance of this action is underscored by the potential impact of the flaw. As of now, U.S. Cybersecurity and Infrastructure Security Agency (CISA) reports no known exploitation.
Administrators are urged to confirm the installation of the patch by using the cplp list command to verify LivePatch statuses. Furthermore, it is crucial to ensure that Trusted Clients settings are restricted to known hosts, preventing unauthorized Internet access to management systems.
Affected Systems and Recommendations
The vulnerability impacts several Check Point branches, including R82.10 with Jumbo Hotfix Take 44 or below, and others as specified. Notably, R82.20 is also vulnerable, lacking a protective Jumbo Hotfix at present, as per Censys.
Standalone deployments, Log Servers, and Multi-Domain servers are equally affected, although the Smart-1 Cloud service remains secure with the fix already applied. Check Point assures that even out-of-support versions can receive fixes upon request.
Administrators should diligently apply the necessary patches and verify client access settings to mitigate potential risks. Despite no current exploitation, the severity of the flaw necessitates immediate action to safeguard systems.
As the fifth significant management flaw since July, vigilance remains crucial in protecting against potential threats. Check Point continues to monitor the situation closely, providing necessary updates and support to its customers.
