Executive brief
A security vulnerability exists in the Gaia Portal, the web-based management interface for Check Point security gateways and management servers. An authorized user who is only supposed to have 'read-only' access can exploit this flaw to gain full administrative (root) control over the system. This could allow an attacker to modify security policies, access sensitive configuration data, or disrupt network operations.
Technical details
This vulnerability is classified as improper privilege management (CWE-269) within the Gaia Portal web interface. An authenticated attacker with low-level (read-only) Gaia Portal privileges can exploit the system to execute arbitrary commands with root-level authority. The attack vector is network-based, though it requires existing authentication and is characterized by high complexity. The flaw affects multiple versions of Quantum Security Gateway and Security Management software, including legacy versions. Fixes are available in recent Jumbo Hotfix Accumulators for R81.20, R82, and R82.10.
Affected products
- Check Point Quantum Security Gateway R82.10 (Jumbo Hotfix Take 36 or below), R82 (Jumbo Hotfix Take 118 or below), R81.20 (Jumbo Hotfix Take 158 or below), R81.10, R81, R80.30, R80.20, R80.10, R80, R77.30
- Check Point Quantum Security Management R82.10 (Jumbo Hotfix Take 36 or below), R82 (Jumbo Hotfix Take 118 or below), R81.20 (Jumbo Hotfix Take 158 or below), R81.10, R81, R80.30, R80.20, R80.10, R80, R77.30
Timeline
- 2026-07-14: other: Article created
- 2026-07-22: advisory: Advisory published by Check Point and NVD
- 2026-07-22: patched: Fixes released in Jumbo Hotfix Accumulators