CVE-2026-93616
Received Received - Intake

Directory Traversal and File Upload in Check Point Management Server

Vulnerability report for CVE-2026-93616, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-09-22

Last updated on: 2026-09-22

Assigner: Check Point Software Technologies Ltd.

Description

A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-09-22
Last Modified
2026-09-22
Generated
2026-09-22
AI Q&A
2026-09-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 20 associated CPEs
Vendor Product Version / Range
checkpoint security_management_server to R82.20 (exc)
checkpoint multi-domain_security_management_server to R82.20 (exc)
checkpoint log_server to R82.20 (exc)
checkpoint multi-domain_log_server to R82.20 (exc)
checkpoint smartevent to R82.20 (exc)
checkpoint security_management_server R82.10
checkpoint multi-domain_security_management_server R82.10
checkpoint log_server R82.10
checkpoint multi-domain_log_server R82.10
checkpoint smartevent R82.10
checkpoint security_management_server R81.20
checkpoint multi-domain_security_management_server R81.20
checkpoint log_server R81.20
checkpoint multi-domain_log_server R81.20
checkpoint smartevent R81.20
checkpoint security_management_server R81.10
checkpoint multi-domain_security_management_server R81.10
checkpoint log_server R81.10
checkpoint multi-domain_log_server R81.10
checkpoint smartevent R81.10

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-22 The product uses external input to construct a pathname that is intended to identify a file or directory that is located underneath a restricted parent directory, but the product does not properly neutralize special elements within the pathname that can cause the pathname to resolve to a location that is outside of the restricted directory.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

CVE-2026-93616 is a high-severity vulnerability in Check Point Management Server products. It allows unauthenticated attackers to bypass security controls and upload malicious scripts to the server using directory traversal techniques. These scripts can then be executed, potentially giving attackers full control over the affected system.

Detection Guidance

Review logs for suspicious login attempts with unusually long usernames, core dumps in /var/log/dump/usermode/, and error logs containing directory traversal sequences like "../". Check for unauthorized script uploads or execution attempts on Check Point Management Servers.

Impact Analysis

This vulnerability could allow attackers to gain unauthorized access to your Check Point Management Server, steal sensitive data, install malware, or disrupt network operations. Since it requires no authentication, any internet-facing system could be targeted, leading to severe operational and security consequences.

Compliance Impact

This vulnerability could lead to unauthorized access and data breaches, violating compliance requirements under GDPR, HIPAA, and other regulations. Organizations may face legal penalties, reputational damage, and loss of customer trust if exploited. Immediate patching and mitigation are critical to maintain compliance.

Mitigation Strategies

Restrict access to Management Servers behind a Security Gateway or firewall. Ensure TCP/19009 is only accessible from trusted IP addresses. Configure Trusted Clients in SmartConsole to limit access to internal IP addresses. Update to fixed versions: R82.20 Security Hotfix (TAR) or later Jumbo Hotfix Accumulators for R82.10 (Take 45+), R82 (Take 127+), R81.20 (Take 170+), and R81.10 (Take 192+).

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-93616. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart