CVE Tools

CVE-2026-62144

Management Authentication Bypass and Privilege Escalation

Published: Jul 22, 2026Updated: Jul 24, 2026 Sources: CVE List NVDCWE-287

Description

An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation requires network access to the Management Server without firewall protection or a configuration that does not restrict Trusted Clients.

In plain language

AI Act now

CVE-2026-62144 is an internet-facing flaw in Check Point “quantum security management” and “Multi-Domain Security Management” where attackers can bypass login and run admin commands; if your Management Server is reachable from the internet, a typical small business should treat this as an emergency.

Executive summary

Unauthenticated remote authentication bypass (CWE-287) in Check Point quantum security management / Multi-Domain Security Management allows remote command execution with administrative privileges when the Management Server is reachable and Trusted Client access is not properly restricted.

If affected, business impact
Full admin control of managementPotential gateway command executionService disruption riskCompromise of security operations

What to do now

  1. Check whether your Check Point quantum security management / Multi-Domain Security Management Management Server is reachable from the internet (e.g., public IP exposure, no firewall allowlist).
  2. Verify your “Trusted Client” configuration is restricted (only approved client IPs/accounts allowed) and that unauthenticated remote access is blocked.
  3. Immediately restrict network access to the Management Server to approved management hosts only (tight firewall rules, block all other inbound internet traffic).
  4. Apply the vendor’s recommended mitigations as soon as they’re released, and actively hunt for signs of admin-command activity from unknown sources.
  5. Escalate to your IT/security vendor with CVE-2026-62144 and request an official fixed version timeline, since no patch information is available in our sources.
May need vendor / contractor work

CVSS Vector Breakdown

AV:NAC:LPR:NUI:NS:UC:HI:HA:N
Exploitability
AV:NAttack Vector
Network
AC:LAttack Complexity
Low
PR:NPrivileges Required
None
UI:NUser Interaction
None
Scope
S:UScope
Unchanged
Impact
C:HConfidentiality
High
I:HIntegrity
High
A:NAvailability
None

Weaknesses

Affected Products

Exploitability

No known exploits, KEV entries, or remediation guidance available for this vulnerability yet.

Attack Graph

Products CVE Techniques Tactics

Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/ + scroll to zoom, or go fullscreen.

MITRE ATT&CK

2 techniques
Initial Access
View detailed technique mapping

References

4

Unlock Complete Vulnerability Intelligence

Get the full picture for CVE-2026-62144 and every CVE in our database. Create a free account — no credit card required.

Create Free Account
Plain-language analysis
Impact assessment and exploitation scenario in plain English
Attack graph visualization
Interactive attack path and kill chain mapping
Exploit details & PoC links
ExploitDB, Metasploit, GitHub PoCs with direct links
Nuclei scanner templates
Ready-to-use vulnerability scanner templates
Full remediation guide
Patch instructions, workarounds, and compliance impact
Interactive AI chat
Ask questions about this vulnerability in natural language
Related vulnerabilities
Semantically similar CVEs and attack patterns
REST API & MCP access
Integrate vulnerability data into your workflows