> Source: [sk185222](https://support.checkpoint.com/results/sk/sk185222)

# sk185222 - CVE-2026-18574 - Management Authentication Bypass

| Property | Value |
|----------|-------|
| Solution ID | sk185222 |
| Date Created | 2026-08-01 |
| Last Modified | 2026-08-03 |
| Technical Level | General |
| Products | Security Management Server, Multi-Domain Security Management Server |
| Versions | R82.10, R82, R81.20, R82.10, R81.10 (EOS), R81 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82 |

## Symptoms

- * **Impact:** An unauthenticated attacker may be able to bypass Management authentication and execute arbitrary commands on the Security Management Server. Successful exploitation could result in full compromise of the Security Management system.

  This issue was discovered internally, and Check Point has no indication of active exploits.

* This issue received the ID [CVE-2026-18574](https://www.cve.org/CVERecord?id=CVE-2026-18574).

* **Affected Products and Versions**   

  Products: Security Management Server, Multi-Domain Security Management Server (MDS).  
  Note: Smart-1 Cloud customers are already protected.  
  Versions:  
  * R80, R80.10, R80.20, R80.30, R80.40, R81, R81.10 (all EoS)
  * R81.20, R82, R82.10
* **Conditions:** Successful exploitation requires network access to the Security Management Server.  
  Environments that do not restrict Trusted Clients (GUI clients) or that expose Management services to untrusted networks may have increased exposure.

*

  ### Mitigation

  1. Follow the [Check Point Hardening Best Practices Guide](https://sc1.checkpoint.com/documents/Check_Point_Gateway_and_Management_Hardening/CP_Check_Point_Gateway_and_Management_Hardening.pdf).  

  2. **Restrict Trusted Clients -** Limit Trusted Clients (GUI clients) to authorized IP addresses and networks.  
     To configure Trusted Clients:  
     1. In **SmartConsole** , go to **Manage \& Settings** \> **Permissions \& Administrators** \> **Trusted Clients**.
     2. Double-click the client you want to edit.
     3. In the **Trusted Client** configuration window that opens, restrict access to authorized hosts and subnets only.  
        Make sure do not use "Any" as a Trusted Client definition.
     4. Click **OK** and install the Security policy.

        ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk185152/Trusted_GUI202607220935111.png)
  3. **Protect Management Access**
     1. Restrict Management access using Firewall policy.
     2. Allow Management connectivity only from trusted administrative workstations.
     3. Make sure implied rules protecting control connections are enabled.
     4. Verify that Management services are not exposed to untrusted networks.

  <br />

  Implementing the above measures can significantly reduce exposure until the relevant fix is applied.

## Solution

This problem was fixed. The fix is included in:

* [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 40
* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 122
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 161

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
