A critical stack-based buffer overflow vulnerability, identified as CVE-2026-91843 with a CVSS score of 9.8, allows an unauthenticated remote attacker to execute arbitrary code with root privileges on vulnerable security management and logging systems. This flaw occurs during login when an excessively long attacker-controlled username triggers a stack overflow before authentication completes, potentially exposing sensitive information such as management data, security policies, administrator details, and collected logs, while enabling further compromise of the protected environment through a network-accessible attack requiring low complexity, no privileges, and no user interaction. The vulnerability affects various Check Point products including Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server within specific version ranges, with affected releases comprising R82.20; R82.10 with Jumbo Hotfix Take 44 or earlier; R82 with Take 126 or earlier; R81.20 with Take 166 or earlier; and end-of-support R81.10 with Take 190 or earlier.
We recommend you to refer this link: https://support.checkpoint.com/results/sk/sk1000155[/subscribe_to_unlock_form]
A critical stack-based buffer overflow vulnerability, identified as CVE-2026-91843 with a CVSS score of 9.8, allows an unauthenticated remote attacker to execute arbitrary code with root privileges on vulnerable security management and logging systems. This flaw occurs during login when an excessively long attacker-controlled username triggers a stack overflow before authentication completes, potentially exposing sensitive information such as management data, security policies, administrator details, and collected logs, while enabling further compromise of the protected environment through a network-accessible attack requiring low complexity, no privileges, and no user interaction. The vulnerability affects various Check Point products including Security Management Server, Multi-Domain Security Management Server, Log Server, and Multi-Domain Log Server within specific version ranges, with affected releases comprising R82.20; R82.10 with Jumbo Hotfix Take 44 or earlier; R82 with Take 126 or earlier; R81.20 with Take 166 or earlier; and end-of-support R81.10 with Take 190 or earlier.
We recommend you to refer this link: https://support.checkpoint.com/results/sk/sk1000155[emaillocker id="1283"]
The following reports contain further technical details:
[/emaillocker]