CVE-2026-50751
Awaiting Analysis Awaiting Analysis - Queue
Remote Access VPN Certificate Validation Bypass via IKEv1

Publication date: 2026-06-08

Last updated on: 2026-06-08

Assigner: Check Point Software Technologies Ltd.

Description
A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
CVSS Scores
EPSS Scores
Probability:
Percentile:
Meta Information
Published
2026-06-08
Last Modified
2026-06-08
Generated
2026-06-08
AI Q&A
2026-06-08
EPSS Evaluated
N/A
NVD
EUVD
Affected Vendors & Products
Showing 1 associated CPE
Vendor Product Version / Range
checkpoint remote_access *
Helpful Resources
Exploitability
CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.
Attack-Flow Graph
AI Quick Actions
Instant insights powered by AI
Executive Summary

This vulnerability is a logic flow weakness in the certificate validation process used in Remote Access and Mobile Access when using the deprecated IKEv1 key exchange protocol. It allows an unauthenticated remote attacker to bypass user authentication.

Specifically, the attacker can establish a remote access VPN connection without needing a valid user password.

Impact Analysis

An attacker exploiting this vulnerability can gain unauthorized remote VPN access without valid credentials.

This unauthorized access could lead to potential exposure of internal network resources, data breaches, or further exploitation within the network.

Compliance Impact

This vulnerability allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Such unauthorized access could lead to exposure of sensitive data, potentially violating data protection requirements under standards like GDPR and HIPAA.

Because the vulnerability compromises authentication controls, it may undermine compliance with regulations that mandate strong access controls and protection of personal or health information.

Mitigation Strategies

To mitigate the CVE-2026-50751 vulnerability, it is important to apply the hotfix or patch released by Check Point as soon as possible.

Since the vulnerability affects the deprecated IKEv1 key exchange protocol, disabling or avoiding the use of IKEv1 in favor of more secure protocols (such as IKEv2) is recommended.

Additionally, monitor for any unusual remote access VPN connections that may indicate exploitation attempts.

Chat Assistant
Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-50751. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70
EPSS Chart