CVE-2026-93616

Summary

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

Affected Software

VendorProductVersion RangeStatus
checkpointQuantum Security ManagementR82.20 with no Jumbo Hotfixaffected
checkpointQuantum Security ManagementR82.10 with Jumbo Hotfix Take 44 or belowaffected
checkpointQuantum Security ManagementR82 with Jumbo Hotfix Take 126 or belowaffected
checkpointQuantum Security ManagementR81.20 with Jumbo Hotfix Take 166 or belowaffected
checkpointQuantum Security ManagementR81.10 (EOS) with Jumbo Hotfix Take 190 or belowaffected
checkpointQuantum Security ManagementR81 (EOS)affected
checkpointQuantum Security ManagementR80.40 (EOS)affected
checkpointQuantum Security ManagementR80.30 (EOS)affected
checkpointQuantum Security ManagementR80.20 (EOS)affected
checkpointQuantum Security ManagementR80.10 (EOS)affected
checkpointQuantum Security ManagementR80 (EOS)affected

Weaknesses

  • CWE-22: CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal').

ADP Enrichment

CISA ADP Vulnrichment

  • SSVC:
  • Exploitation: active
    • Automatable: yes
    • Technical Impact: total

Additional References

References