VYPR
patchPublished Sep 16, 2026· 1 source

Critical Check Point Flaw Grants Unauthenticated Root Access

A critical vulnerability (CVE-2026-91843) in Check Point's management and logging systems allows unauthenticated remote attackers to gain root privileges.

Check Point has issued an urgent fix for CVE-2026-91843, a severe stack-based buffer overflow vulnerability that could permit unauthenticated remote attackers to execute arbitrary code with root privileges on vulnerable security management and logging systems. The flaw, rated with a CVSS 3.1 score of 9.8, is particularly dangerous due to its low attack complexity, requiring no privileges or user interaction, and its network accessibility.

The vulnerability is triggered during the login process. An attacker can provide an excessively long username, which overflows a buffer on the stack before the system completes authentication. This overflow can be leveraged to gain the highest level of operating system control, potentially exposing sensitive management data, security policies, administrator credentials, and collected logs. Furthermore, a successful exploit could serve as a gateway for further network compromise.

Check Point has not publicly detailed the specific exploit chain or confirmed any in-the-wild attacks. However, the company has identified several affected products, including Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server. Vulnerable software versions include R82.20; R81.10 and R82.10 with specific Jumbo Hotfix levels or earlier; and end-of-support versions R80 through R80.40 and R81.

Smart-1 Cloud environments are reportedly not vulnerable as the fix has already been deployed. Check Point advises administrators to scrutinize SmartConsole Audit and Admin login records for specific error messages, such as "Administrator failed to log in: Username too long." While this message may indicate an attempted exploit, further investigation of surrounding activity is recommended to confirm a successful root-level compromise.

To aid incident response, organizations should preserve relevant source addresses, timestamps, administrator login events, configuration changes, and any unusual management-server processes. Check Point has delivered the correction via its LivePatch service. Administrators with automatic security updates enabled should receive the patch automatically, but verification is strongly advised. Offline packages are also available for specific versions.

Until the LivePatch is confirmed as installed on all affected management or log servers, Check Point recommends restricting SmartConsole Trusted Clients to approved IP addresses or subnets. The company explicitly warns against configuring the client type to "Any." Given that a compromise would grant root access without requiring authentication, immediate action is critical for exposed management interfaces and unsupported releases, with migration to a supported branch being a priority alongside applying the security fix.

Synthesized by Vypr AI