CVE-2026-91843, Check Point Security Management / Multi-Domain Security Management / Log Server: unauthenticated stack overflow in the login process reaches root RCE (CVSS 9.8)
An oversized username in Check Point's management login reaches root, patch or restrict management-plane access now
Defender actions
- Apply the CVE-2026-91843 LivePatch (confirm
cplp listin Expert mode shows it armed) to every Check Point Security Management, Multi-Domain Security Management, Log Server and Multi-Domain Log Server now, and verify no Trusted Client/GUI access to the login interface reaches it from outside the management network.
Analysis
Check Point disclosed CVE-2026-91843 (CVSS 9.8) on 2026-09-16: a stack-based buffer overflow in the unauthenticated login process to Check Point Security Management Server, Multi-Domain Security Management Server, Log Server and Multi-Domain Log Server lets an attacker who reaches the login interface send an oversized username to overflow the stack and execute arbitrary code as root, without valid credentials or user interaction (Check Point PSIRT, 2026-09-16). No source (Check Point's own advisory, BSI CERT-Bund, or CERT-FR) reports observed exploitation (Check Point PSIRT, 2026-09-16; CERT-FR CERTFR-2026-AVI-1193, 2026-09-17). Check Point ships the fix as a LivePatch rather than a full upgrade: administrators with automatic updates enabled per sk175504 are already protected, and cplp list in Expert mode should show the CVE-2026-91843 patch armed on affected R82.20, R82.10, R82 and R81.20 builds; R81.10 and earlier R80.x/R81 lines are past end-of-support and remain unpatched (Check Point PSIRT, 2026-09-16). The management login service should not normally be internet-facing, but any organization that exposes it, directly or via an overlooked NAT or VPN path, is a single unauthenticated request away from root on the box that holds every firewall policy and credential in the fleet, which is why this clears the bar for action despite no confirmed exploitation.
Triage: Check Point's own SmartConsole Audit/Admin login log entry "Administrator failed to log in: Username too long" is the exploitation-attempt signature; a genuine failed login records a normal username-length failure, so this specific message text appearing where no legitimate oversized-username attempt occurred is the discriminator (Check Point PSIRT, 2026-09-16).
Cited evidence
A stack overflow during the unauthenticated login process may allow an attacker to run arbitrary code remotely with root privileges.
In SmartConsole, search for Audit and Admin login logs containing the message: "Administrator failed to log in: Username too long".
Sources3
AI-generated · no human review · this permalink is the shareable record for the finding · verify operationally critical claims against the linked primary source.