Urgent.News

What's breaking now, across thousands of outlets.

Tech

How a Pre-Authentication Stack Overflow in Check Point Log Servers Leads to Root Code Execution

How a Pre-Authentication Stack Overflow in Check Point Log Servers Leads to Root Code Execution A pre-authentication bug with root consequences CVE-2026-91843 affects the login path of Check Point Security Management and Log Servers. The vulnerable code runs before any credential check, so an unauthenticated attacker who can reach the service can trigger it. CERT-In recorded the issue as…

An unchecked vulnerability, CVE-2026-91843, exists in the login process of Check Point Security Management and Log Servers. This flaw occurs due to a pre-authentication stack overflow, which is a bug that can be exploited by an unauthenticated attacker. The attacker reaches the service over the network and sends a specially crafted request to the login process.

This triggers a stack overflow, corrupting control data on the stack, and ultimately redirects execution. The attacker is able to run arbitrary code with root privileges, bypassing any authentication measures that normally stand in their way.

This vulnerability is particularly dangerous because Security Management and Log Servers in Check Point deployments are responsible for defining policy, holding gateway configuration, and storing security events. Root access on these servers allows attackers to make policy changes, manipulate logs, and move laterally toward managed gateways.

The affected releases include Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server across various versions of Check Point's software.

To mitigate the risk of this exploit, Check Point has released updates, which should be installed as soon as possible. Until then, network administrators should limit exposure of the login service, apply network access controls to management interfaces, and monitor logs for any unusual login attempts.

Written by urgent.news from Dev.to's reporting — not their text. Machine-written — may contain errors; check the original before relying on it.

Read the original at dev.to →

More in Tech

More from Sunday 20 September →