CVE-2026-50751

A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Configurations

Configuration 1 (hide)

OR cpe:2.3:o:checkpoint:gaia_os:*:*:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:-:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_10:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_101:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_103:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_105:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_111:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_113:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_115:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_118:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_119:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_120:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_122:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_126:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_127:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_14:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_141:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_24:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_26:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_38:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_41:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_43:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_45:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_53:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_54:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_65:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_70:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_76:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_79:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_8:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_84:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_89:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_90:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_92:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_96:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_98:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r81.20:take_99:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:-:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_10:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_103:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_12:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_14:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_18:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_19:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_25:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_33:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_34:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_36:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_39:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_41:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_43:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_44:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_60:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_73:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82:take_91:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82.10:-:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82.10:take_19:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_os:r82.10:take_6:*:*:*:*:*:*

Configuration 2 (hide)

AND
OR cpe:2.3:o:checkpoint:gaia_embedded:*:*:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_embedded:r81.10.17:-:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_embedded:r81.10.17:build_996004508:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_embedded:r81.10.17:build_996004620:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_embedded:r81.10.17:build_996004653:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_embedded:r81.10.17:build_996004721:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_embedded:r81.10.17:build_996004892:*:*:*:*:*:*
OR cpe:2.3:h:checkpoint:quantum_spark_1530:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_1550:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_1570:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_1570r:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_1590:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_1595r:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_1600:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_1800:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_1900:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_2000:-:*:*:*:*:*:*:*

Configuration 3 (hide)

AND
OR cpe:2.3:o:checkpoint:gaia_embedded:*:*:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_embedded:r82.00.10:-:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_embedded:r82.00.10:build_998001559:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_embedded:r82.00.10:build_998001562:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_embedded:r82.00.10:build_998002110:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_embedded:r82.00.10:build_998002112:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_embedded:r82.00.10:build_998002133:*:*:*:*:*:*
cpe:2.3:o:checkpoint:gaia_embedded:r82.00.10:build_998002203:*:*:*:*:*:*
OR cpe:2.3:h:checkpoint:quantum_spark_1535:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_1555:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_1575:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_1575r:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_2530:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_2550:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_2560:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_2570:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_2580:-:*:*:*:*:*:*:*
cpe:2.3:h:checkpoint:quantum_spark_2590:-:*:*:*:*:*:*:*

History

No history.

Information

Published : 2026-06-08 12:16

Updated : 2026-08-04 05:16


NVD link : CVE-2026-50751

Mitre link : CVE-2026-50751

CVE.ORG link : CVE-2026-50751


JSON object : View

Products Affected

checkpoint

  • quantum_spark_2000
  • quantum_spark_1590
  • quantum_spark_1575r
  • quantum_spark_1570r
  • quantum_spark_1595r
  • quantum_spark_1575
  • gaia_embedded
  • quantum_spark_1535
  • quantum_spark_2550
  • quantum_spark_2570
  • quantum_spark_2580
  • quantum_spark_1900
  • quantum_spark_1555
  • quantum_spark_1550
  • quantum_spark_1530
  • quantum_spark_2530
  • quantum_spark_2560
  • gaia_os
  • quantum_spark_2590
  • quantum_spark_1800
  • quantum_spark_1570
  • quantum_spark_1600
CWE
CWE-287

Improper Authentication