CRITICAL · 9.3

CVE-2026-50751

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a...

Vulnerability Description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

CVSS Score

9.3

CRITICAL

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:L/A:N
Attack Vector
NETWORK
Attack Complexity
LOW
Privileges Required
NONE
User Interaction
NONE
Scope
CHANGED
Confidentiality
HIGH
Integrity
LOW
Availability
NONE

Affected Products

VendorProductVersions
CheckpointGaia Os>= r80.40, < r81.20
CheckpointGaia Embedded>= r80.20.00, < r81.10.17
CheckpointQuantum Spark 1530-
CheckpointQuantum Spark 1550-
CheckpointQuantum Spark 1570-
CheckpointQuantum Spark 1570R-
CheckpointQuantum Spark 1590-
CheckpointQuantum Spark 1595R-
CheckpointQuantum Spark 1600-
CheckpointQuantum Spark 1800-
CheckpointQuantum Spark 1900-
CheckpointQuantum Spark 2000-
CheckpointQuantum Spark 1535-
CheckpointQuantum Spark 1555-
CheckpointQuantum Spark 1575-
CheckpointQuantum Spark 1575R-
CheckpointQuantum Spark 2530-
CheckpointQuantum Spark 2550-
CheckpointQuantum Spark 2560-
CheckpointQuantum Spark 2570-

Related Weaknesses (CWE)

References

FAQ

What is CVE-2026-50751?

CVE-2026-50751 is a vulnerability with a CVSS score of 9.3 (CRITICAL). A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a...

How severe is CVE-2026-50751?

CVE-2026-50751 has been rated CRITICAL with a CVSS base score of 9.3/10. This is considered a critical vulnerability requiring immediate attention.

Is there a patch for CVE-2026-50751?

Check the references section above for vendor advisories and patch information. Affected products include: Checkpoint Gaia Os, Checkpoint Gaia Embedded, Checkpoint Quantum Spark 1530, Checkpoint Quantum Spark 1550, Checkpoint Quantum Spark 1570.