CVE-2026-10847

HIGH

Check Point Identity Agent < 81.087.0000 - Local Privilege Escalation

Title source: manual
STIX 2.1

Description

A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an attacker to gain elevated privileges on the affected Windows endpoint.

References (1)

Core 1
Core References
Vendor Advisory vendor-advisory
Check Point Security Advisory for CVE-2026-10847
https://support.checkpoint.com/results/sk/sk185052

Scores

CVSS v3 7.8
EPSS 0.0012
EPSS Percentile 2.2%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-427
Status published
Products (1)
checkpoint/Identity Agent Versions prior to 81.087.0000
Published Jun 11, 2026
Tracked Since Jun 11, 2026