Skip to main content
Vulnerability Database/CVE-2026-93616

CVE-2026-93616: Checkpoint Multi-domain Path Traversal Flaw

CVE-2026-93616 is a path traversal vulnerability in Checkpoint Multi-domain Security Management that enables unauthenticated attackers to upload and execute malicious scripts. This article covers technical details, affected versions, impact assessment, and mitigation strategies.

Published:

CVE-2026-93616 Overview

CVE-2026-93616 is a pre-authentication directory traversal and file upload vulnerability affecting Check Point Quantum Security Management and Multi-Domain Security Management servers. An unauthenticated remote attacker can traverse the filesystem and upload arbitrary scripts to server-controlled locations. Once written to an executable path, those scripts can be invoked to achieve remote code execution on the management server. The vulnerability is tracked under CWE-22: Improper Limitation of a Pathname to a Restricted Directory and has been confirmed by Check Point as under active exploitation. CISA has added CVE-2026-93616 to its Known Exploited Vulnerabilities catalog.

Critical Impact

Unauthenticated attackers can gain remote code execution on Check Point management servers, giving them control of the security policy plane that governs downstream firewall gateways.

Affected Products

  • Check Point Quantum Security Management (R81.10, R81.20, R82, R82.10, R82.20)
  • Check Point Multi-Domain Security Management (R81.10, R81.20, R82, R82.10, R82.20)
  • All listed Take (hotfix) levels for the above releases prior to the fix

Discovery Timeline

  • 2026-09-22 - CVE-2026-93616 published to the National Vulnerability Database
  • 2026-09-23 - Last updated in NVD database
  • 2026-09-24 - EPSS score recorded at 2.421% (83.47 percentile)
  • Confirmed - Listed by CISA in the Known Exploited Vulnerabilities catalog

Technical Details for CVE-2026-93616

Vulnerability Analysis

The flaw combines two primitives: a path traversal weakness and an unauthenticated file upload endpoint on the management plane. Because the affected endpoint is reachable without credentials, an attacker only needs network access to the management interface to trigger the vulnerability. The traversal primitive lets the attacker escape the intended upload directory and place attacker-controlled content anywhere the web service can write. When the uploaded artifact is a script placed in an executable or auto-invoked location, the attacker gains code execution in the context of the management service. Compromise of a Check Point management server is high-impact because that server centrally manages policy, logs, and configuration for all managed gateways.

Root Cause

The root cause is missing or insufficient canonicalization of user-supplied file path components in the upload handler. The service accepts filename or path parameters and joins them to a base directory without rejecting .. sequences, absolute paths, or encoded traversal payloads. Combined with the absence of authentication on the affected endpoint, this input-handling defect ([CWE-22]) exposes the entire filesystem writable by the service account.

Attack Vector

Exploitation is network-based against the management server's exposed HTTP(S) interface. The attacker issues a crafted upload request whose filename or path parameter contains directory traversal sequences, targeting a directory from which the operating system or web service will execute the file. No credentials, user interaction, or prior foothold are required. Check Point's advisory confirms in-the-wild exploitation, so any internet-reachable or broadly accessible management interface should be treated as at risk. See the Check Point Security Advisory and the Check Point Support Article sk1000171 for vendor guidance.

No public proof-of-concept has been released. A prose description is provided here in place of exploit code.

Detection Methods for CVE-2026-93616

Indicators of Compromise

  • Unexpected files, especially scripts (.sh, .pl, .py, .cgi), appearing under management server web directories or temporary upload paths
  • HTTP requests to management endpoints containing ..%2f, ../, or absolute paths in filename or path parameters
  • Child processes spawned by the management web service (for example, sh, bash, perl, python) outside normal maintenance windows
  • Outbound connections from the management server to unfamiliar IP addresses or reverse-shell listeners

Detection Strategies

  • Inspect management server web access logs for POST or PUT requests targeting upload endpoints with traversal patterns in parameters or headers
  • Monitor filesystem integrity for new or modified files in directories writable by the management service account
  • Correlate authentication logs with file creation events to identify writes that occur without a preceding administrative session
  • Alert on new persistence artifacts such as cron entries, systemd units, or modified startup scripts on management servers

Monitoring Recommendations

  • Forward management server logs, process creation events, and network telemetry to a central SIEM for correlation
  • Baseline normal administrative traffic to the management interface and alert on off-hours or non-administrator source IPs
  • Track egress from management servers; these hosts should have a narrow, well-defined communication profile

How to Mitigate CVE-2026-93616

Immediate Actions Required

  • Apply the Check Point hotfixes referenced in sk1000171 to all Quantum and Multi-Domain Security Management servers
  • Restrict network reachability of the management interface to a dedicated administrative network or jump host; do not expose it to the internet
  • Hunt for indicators of compromise on any management server that was reachable prior to patching, given confirmed active exploitation
  • Rotate administrator credentials, API keys, and certificates stored on any potentially compromised management server

Patch Information

Check Point has published fixed Take levels for R81.10, R81.20, R82, R82.10, and R82.20 through knowledge base article sk1000171. Administrators should identify their current release and Take, then install the corresponding fixed hotfix. Because CVE-2026-93616 is on the CISA Known Exploited Vulnerabilities catalog, federal agencies are required to remediate within the KEV due date, and other organizations should treat patching as urgent.

Workarounds

  • Place the management interface behind a VPN or bastion host so it is not reachable from untrusted networks
  • Apply firewall rules on the management server to permit inbound HTTPS only from a small allow-list of administrator IPs
  • Enable enhanced logging on the management web service and forward events off-box to preserve evidence if the host is compromised
  • Review and reduce the set of management APIs and services exposed on the network interface
bash
# Example: restrict inbound access to the management interface to trusted admin subnet
# Replace 10.10.0.0/24 with your administrative network and eth0 with the management NIC
iptables -A INPUT -i eth0 -p tcp --dport 443 -s 10.10.0.0/24 -j ACCEPT
iptables -A INPUT -i eth0 -p tcp --dport 443 -j DROP
iptables -A INPUT -i eth0 -p tcp --dport 80  -j DROP

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.