CVE-2026-50751
Analyzed Analyzed - Analysis Complete

Remote Access VPN Certificate Validation Bypass via IKEv1

Vulnerability report for CVE-2026-50751, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-06-08

Last updated on: 2026-06-09

Assigner: Check Point Software Technologies Ltd.

Description

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-06-08
Last Modified
2026-06-09
Generated
2026-06-28
AI Q&A
2026-06-08
EPSS Evaluated
2026-06-27
NVD
EUVD

Affected Vendors & Products

Showing 73 associated CPEs
Vendor Product Version / Range
checkpoint gaia_os From r80.40 (inc) to r81.20 (exc)
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r81.20
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82
checkpoint gaia_os r82.10
checkpoint gaia_os r82.10
checkpoint gaia_os r82.10
checkpoint gaia_embedded From r80.20.00 (inc) to r81.10.17 (exc)
checkpoint gaia_embedded r81.10.17
checkpoint gaia_embedded r81.10.17
checkpoint gaia_embedded r81.10.17
checkpoint gaia_embedded r81.10.17
checkpoint gaia_embedded r81.10.17
checkpoint gaia_embedded r81.10.17
checkpoint gaia_embedded From r80.20.00 (inc) to r82.00.10 (exc)
checkpoint gaia_embedded r82.00.10
checkpoint gaia_embedded r82.00.10
checkpoint gaia_embedded r82.00.10
checkpoint gaia_embedded r82.00.10
checkpoint gaia_embedded r82.00.10
checkpoint gaia_embedded r82.00.10
checkpoint gaia_embedded r82.00.10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Compliance Impact

This vulnerability allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Such unauthorized access could lead to exposure of sensitive data, potentially violating data protection requirements under standards like GDPR and HIPAA.

Because the vulnerability compromises authentication controls, it may undermine compliance with regulations that mandate strong access controls and protection of personal or health information.

Executive Summary

This vulnerability is a logic flow weakness in the certificate validation process used in Remote Access and Mobile Access when using the deprecated IKEv1 key exchange protocol. It allows an unauthenticated remote attacker to bypass user authentication.

Specifically, the attacker can establish a remote access VPN connection without needing a valid user password.

Impact Analysis

An attacker exploiting this vulnerability can gain unauthorized remote VPN access without valid credentials.

This unauthorized access could lead to potential exposure of internal network resources, data breaches, or further exploitation within the network.

Mitigation Strategies

To mitigate the CVE-2026-50751 vulnerability, it is important to apply the hotfix or patch released by Check Point as soon as possible.

Since the vulnerability affects the deprecated IKEv1 key exchange protocol, disabling or avoiding the use of IKEv1 in favor of more secure protocols (such as IKEv2) is recommended.

Additionally, monitor for any unusual remote access VPN connections that may indicate exploitation attempts.

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50751. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart