A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.

Project Subscriptions

No data.

Advisories

No advisories yet.

Fixes

Solution

No solution given by the vendor.


Workaround

No workaround given by the vendor.

History

Mon, 08 Jun 2026 11:45:00 +0000

Type Values Removed Values Added
Description A logic flow weakness in Remote Access and Mobile Access certificate validation in deprecated IKEv1 key exchange allows an unauthenticated remote attacker to bypass user authentication and establish a remote access VPN connection without a valid user password.
Title User Authentication Bypass in VPN Remote Access and Mobile Access
Weaknesses CWE-287
References

Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: checkpoint

Published:

Updated: 2026-06-08T11:07:15.746Z

Reserved: 2026-06-07T09:42:08.251Z

Link: CVE-2026-50751

cve-icon Vulnrichment

No data.

cve-icon NVD

Status : Received

Published: 2026-06-08T12:16:32.367

Modified: 2026-06-08T12:16:32.367

Link: CVE-2026-50751

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-06-08T12:30:23Z

Weaknesses