CVE-2026-93616
Vulnerability Summary
Timeline
Description
A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.
CVSS Metrics
- v3.1•CRITICAL•Score: 9.8CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Techniques & Countermeasures
- CWE-22•Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.
Affected Systems
- checkpoint•quantum security management
R82.20 with no Jumbo Hotfix | R82.10 with Jumbo Hotfix Take 44 or below | R82 with Jumbo Hotfix Take 126 or below | R81.20 with Jumbo Hotfix Take 166 or below | R81.10 (EOS) with Jumbo Hotfix Take 190 or below | R81 (EOS) | R80.40 (EOS) | R80.30 (EOS) | R80.20 (EOS) | R80.10 (EOS) | R80 (EOS)
References (3)
- https://support.checkpoint.com/results/sk/sk1000171
- https://blog.checkpoint.com/security/security-advisory-action-required-active-exploitation-of-cve-2026-85102-and-a-management-pre-authentication-vulnerability-cve-2026-93616/
- https://www.cisa.gov/known-exploited-vulnerabilities-catalog?field_cve=CVE-2026-93616