> Source: [sk1000155](https://support.checkpoint.com/results/sk/sk1000155)

# sk1000155 - CVE-2026-91843 - Stack overflow in login process to the Security Management and Log Servers

| Property | Value |
|----------|-------|
| Solution ID | sk1000155 |
| Date Created | 2026-09-16 |
| Last Modified | 2026-09-16 |
| Technical Level | General |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R82.20, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.20 |

## Symptoms

- * **Issue:** A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
* This issue received the ID [CVE-2026-91843](https://www.cve.org/CVERecord?id=CVE-2026-91843) and a CVSS score of 9.8.
* **Affected Products:** Security Management Server, Multi-Domain Security Management Server, Log Server, Multi-Domain Log Server.  
  **Note: The Smart-1 Cloud environment is not affected** because the fix has already been implemented there.
* **Affected Versions:**
  * R82.20
  * R82.10 Jumbo Hotfix Take 44 or lower
  * R82 Jumbo Hotfix Take 126 or lower
  * R81.20 Jumbo Hotfix Take 166 or lower
  * R81.10 Jumbo Hotfix Take 190 or lower (EoS)
  * R80, R80.10, R80.20, R80.30, R80.40, R81 (all EoS)

### How to identify an attack

* In SmartConsole, search for Audit and Admin login logs containing the message: `"Administrator failed to log in: Username too long".`  
  ![](https://static.checkpoint.com/apps/sk/1000155/600b4e74-5abe-4acf-9936-8ded67f89aff.png)

### Mitigation

1. Follow the [Check Point Gateway and Management Hardening Administration Guide](https://sc1.checkpoint.com/documents/Check_Point_Gateway_and_Management_Hardening/Hardening_GW_and_MGMT/Introduction.html).
2. Limit **Trusted Clients** (GUI clients) to trusted IP addresses/subnets.   
   To do so,
   1. In **SmartConsole** , go to **Manage \& Settings** \> **Permissions \& Administrators** \> **Trusted Clients**.
   2. Double-click the client you want to edit.
   3. In the **Trusted Client** configuration window that opens, change the settings as needed.   
      Make sure do not to use "Any" as a Client Type.
   4. Click **OK** .


      ![](https://static.checkpoint.com/apps/sk/1000155/8cb9d964-4cf8-4859-a439-4f9d863fd4ce.png)

## Solution

This problem was fixed. The fix is included in [Check Point LivePatch](https://support.checkpoint.com/results/sk/sk185114).

If you have enabled automatic updates according to [sk175504](https://support.checkpoint.com/results/sk/sk175504 "https://support.checkpoint.com/results/sk/sk175504"), you are automatically protected.

**Manual Check Point LivePatch installation**

Download the offline package from the table below:

|------------|-------------------------------------------------------------|--------------------------------------------------------------------------------------------------------------------------|
| Version    | Take Number                                                 | Download Package                                                                                                         |
| **R82.20** | BUNDLE_URGENT_SECURITY_UPDATE_R82_10_AUTOUPDATE **take 29** | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/145556) (TAR) |
| **R82.10** | BUNDLE_URGENT_SECURITY_UPDATE_R82_10_AUTOUPDATE **take 28** | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/145555) (TAR) |
| **R82**    | BUNDLE_URGENT_SECURITY_UPDATE_R82_AUTOUPDATE **take 28**    | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/145554) (TAR) |
| **R81.20** | BUNDLE_URGENT_SECURITY_UPDATE_R81_20_AUTOUPDATE **take 28** | [![](https://sc1.checkpoint.com/sc/images/download-m.png)](https://support.checkpoint.com/results/download/145553) (TAR) |

For instructions on the offline package installation procedure, refer to [sk185114](https://support.checkpoint.com/results/sk/sk185114).

This LivePatch should be installed on all Security Management / Multi-Domain Security Management / Log Servers.

<br />

For LivePatch validation, run in Expert mode on the Security Management Server / Log Server: cplp list

Expected output:

```
[Expert@MGMT]# cplp list
ID(PATCH:PROC) � � � �STATUS �MODE � � � � � �COMMENT
--------------------------------------------------------------------------
fwm:fwm � � � � � � � armed  �livepatch � � CVE-2026-91843
```

<br />

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
