Check Point Vulnerability Lets Remote Hackers Gain Root Access Without Authentication
Check Point patched CVE-2026-91843, a CVSS 9.8 pre-auth stack overflow granting remote root on Security Management and Log Servers.
Check Point released an urgent fix for CVE-2026-91843 (CVSS 3.1: 9.8), a stack-based buffer overflow triggered by an excessively long username during login that lets an unauthenticated remote attacker execute arbitrary code with root privileges. Affected products include Security Management Server, Multi-Domain Security Management Server, and Log Servers across releases from R80 through R82.20, with fixes delivered via LivePatch and urgent Take packages. The vendor reports no observed exploitation in the wild, and administrators are advised to verify patch deployment and restrict SmartConsole Trusted Clients.
- Oversized attacker-controlled username triggers stack overflow before authentication completes
- Compromise would expose management data, security policies, admin details, and collected logs
- Detection hint: 'Administrator failed to log in: Username too long' in SmartConsole Audit records
- Smart-1 Cloud already patched; end-of-support R80 and R81 releases remain affected
Vulnerabilities mentionedAll →
| CVE | Vulnerability | CVSS | EPSS | Flags | Affected | Exposure | Published |
|---|---|---|---|---|---|---|---|
| CVE-2026-91843 | Unauthenticated stack overflow gives root RCE in Check Point login process CVE-2026-91843 is a stack-based buffer overflow (CWE-121) in the unauthenticated login process of a Check Point product, as Check Point Software ([email protected]) is the assigning CNA and its CVE scope covers Check Point products. An attacker can trigger the flaw remotely by sending crafted input to the login interface before authenticating, with no user interaction or credentials required. Successful exploitation allows arbitrary code execution with root privileges, the highest level of control on the affected system. The vulnerability is rated 9.8 Critical (AV:N/AC:L/PR:N/UI:N, all impacts high), reflecting trivial network exploitability. No public proof-of-concept or confirmed in-the-wild exploitation is known at this time, and the source data does not name the specific product line or affected version ranges. Do: Monitor Check Point's official advisory channels for the affected product/version list and patch release, and upgrade as soon as fixed versions are published. In the interim, restrict the login/management interface of Check Point appliances to trusted management networks and remove any direct internet exposure, and review perimeter logs for anomalous pre-authentication traffic against that interface. | 9.8 | — |
| — |
Full article528 words · extracted from cybersecuritynews.com · click to collapse
Check Point has released an urgent security fix for CVE-2026-91843, a critical stack-based buffer overflow that could let an unauthenticated remote attacker execute arbitrary code with root privileges on vulnerable security management and logging systems.
The flaw carries a CVSS 3.1 score of 9.8, reflecting a network-accessible attack requiring low complexity, no privileges, and no user interaction.
The vulnerability occurs during login, where an excessively long attacker-controlled username can trigger a stack overflow before authentication completes.
Successful exploitation could give an adversary the highest level of operating-system control, potentially exposing management data, security policies, administrator information, and collected logs while enabling further compromise of the protected environment.
Check Point Vulnerability Enables Root Access
Check Point has not publicly described the exploit chain or said it has observed attacks in the wild. Affected products include Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server.
Vulnerable releases comprise R82.20; R82.10 with Jumbo Hotfix Take 44 or earlier; R82 with Take 126 or earlier; R81.20 with Take 166 or earlier; and end-of-support R81.10 with Take 190 or earlier. R80 through R80.40 and R81, which are also end-of-support, remain affected.
According to the advisory published by Check Point, Check Point says Smart-1 Cloud is not vulnerable because the correction has already been deployed in that environment.
Defenders should immediately examine SmartConsole Audit and Admin login records for the message “Administrator failed to log in: Username too long.”
This entry may indicate an attempt to deliver the oversized input associated with the flaw, although teams should investigate surrounding activity before treating it as proof of successful root-level compromise.
Preserve relevant source addresses, timestamps, administrator login events, configuration changes, and unusual management-server processes for incident-response analysis.
Check Point has delivered the correction through Check Point LivePatch. Customers with automatic security updates enabled under sk175504 should receive protection automatically, but administrators should verify deployment rather than assume coverage.
Offline packages are available as urgent security update Take 29 for R82.20 and Take 28 for R82.10, R82, and R81.20. The LivePatch must be installed across every affected Security Management, Multi-Domain Security Management, and Log Server.
Administrators can validate protection by entering Expert mode and running cplp list on each management or log server. A protected system should show the fwm:fwm patch in “armed” status with “livepatch” mode and CVE-2026-91843 in the comment field.
Until remediation is confirmed, organizations should restrict SmartConsole Trusted Clients to approved IP addresses or subnets through Manage & Settings, Permissions & Administrators, and Trusted Clients.
Check Point specifically warns against selecting “Any” as the client type. Because compromise would yield root access without credentials, exposed management interfaces and unsupported releases warrant immediate action, with migration to a supported branch treated as a priority rather than a substitute for applying the available fix.
Cut every SOC alert investigation by 21 min. Power your SOC with instant IOC context for immediate response: Integrate TI Lookup in your SOC
Guru Baranhttps://cybersecuritynews.com
Gurubaran KS is a cybersecurity analyst, and Journalist with a strong focus on emerging threats and digital defense strategies. He is the Co-Founder and Editor-in-Chief of Cyber Security News, where he leads editorial coverage on global cybersecurity developments.
Text extracted automatically; images, tables and formatting may be missing. Original: https://cybersecuritynews.com/check-point-root-access-flaw/