CVE-2026-62145 Details
Description
A vulnerability in Check Point Gaia Portal allows an authenticated attacker with read-only Gaia Portal privileges to execute commands with root privileges.
A local privilege escalation vulnerability has been identified in Check Point Gaia Portal. This issue allows an authenticated attacker with read-only privileges to execute commands with root access. The vulnerability affects multiple versions of the Gaia operating system across Check Point Security Gateways and Security Management products, except for Check Point Spark Gateways.
To address this vulnerability, users should update to the latest versions available in the Jumbo Hotfix Accumulator for R82.10 (starting from Take 36), R82 (starting from Take 118), and R81.20 (starting from Take 158). Additionally, it is recommended to restrict Gaia OS admin access to trusted hosts or subnets, enable Multi-Factor Authentication for administrators, and consult the Check Point Gateway and Management Hardening Best Practices Guide for further guidance.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jul 23, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.checkpoint.com/results/sk/sk185153 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-269 | Improper Privilege Management | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | CVE Modified | CISA-ADP |
| Jul 22, 2026 | New CVE Received | [email protected] |