CVE-2026-62145
Local Privilege Escalation in Gaia Portal
Description
A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
In plain language
AI Act nowCVE-2026-62145 lets an attacker who already has low-level access to Check Point Gaia Portal run commands as the system’s super-user (root); this has been reported as exploited, so you should treat it as urgent if your gateway/management services are reachable from the network.
CVE-2026-62145 is a local privilege escalation in Check Point Gaia Portal where an authenticated user with read-only Gaia Portal access can execute arbitrary commands as root (network-reachable; no user interaction).
What to do now
- Check whether your Check Point “Gaia Portal” is reachable over the network (especially from any untrusted networks) and whether any “read-only” Gaia Portal users exist.
- Confirm your current software versions for “quantum security gateway” and “quantum security management” against the latest vendor security advisories for CVE-2026-62145.
- If an update is not yet available, immediately restrict network reachability to the Gaia Portal / management interfaces (allow only trusted source IPs, and do not leave Trusted Clients unrestricted).
- Remove or reduce read-only Gaia Portal access: eliminate unused accounts and ensure only required staff have Gaia Portal access.
- Create a short-term monitoring plan for post-login behavior and command execution attempts from Gaia Portal accounts, and review logs for suspicious administrative actions.
CVSS Vector Breakdown
AV:NAttack VectorAC:HAttack ComplexityPR:LPrivileges RequiredUI:NUser InteractionS:UScopeC:HConfidentialityI:HIntegrityA:HAvailabilityWeaknesses
Affected Products
Exploitability
Attack Graph
Click technique nodes for MITRE ATT&CK details · drag to pan · Ctrl/⌘ + scroll to zoom, or go fullscreen.
MITRE ATT&CK
1 techniqueReferences
- CVE-2026-16232: Critical Check Point SmartConsole Authentication Bypass Exploited in the Wilden·Rapid7 Blog· Exploited Security Management auth-bypass
- Attackers exploit critical Check Point flaw to take over firewall management (CVE-2026-16232)en-us·Help Net Security· Exploited Check Point Security Management auth-bypass
- New Check Point Zero-Day Vulnerability Exploited in the Wilden-us·SecurityWeek· Exploited Security Management zero-day
- Check Point Patches Exploited SmartConsole Flaw Allowing Full Admin Accessen·The Hacker News· Exploited SmartConsole zero-day
Unlock Complete Vulnerability Intelligence
Get the full picture for CVE-2026-62145 and every CVE in our database. Create a free account — no credit card required.
Create Free Account