CVE Explorer
CVE-2026-10847
A local privilege escalation vulnerability exists in Check Point Identity Agent Full for Windows OS. An authenticated local user may be able to execute arbitrary code with SYSTEM privileges due to improper handling of executable resolution during the log collection process. Successful exploitation could allow an attacker to gain elevated privileges on the affected Windows endpoint.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
0
Affected products and versions
1 source assertion{"product":"Identity Agent","vendor":"checkpoint","versions":[{"status":"affected","version":"Versions prior to 81.087.0000"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:c4851542d283095be1fad51a855e6527c0d5388e4fc9276a0e478c11bda9a928 · sha256:5da657b5af4e3f75… · /containers/cna/affected/0
Provider-owned CVSS observations
1 source assertion{"metric":{"attackComplexity":"LOW","attackVector":"LOCAL","availabilityImpact":"HIGH","baseScore":7.8,"baseSeverity":"HIGH","confidentialityImpact":"HIGH","integrityImpact":"HIGH","privilegesRequired":"LOW","scope":"UNCHANGED","userInteraction":"NONE","vectorString":"CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H","version":"3.1"},"metric_type":"cvssV3_1"}
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:c4851542d283095be1fad51a855e6527c0d5388e4fc9276a0e478c11bda9a928 · sha256:5da657b5af4e3f75… · /containers/cna/metrics/0/cvssV3_1
CWE assertions
1 source assertion{"cweId":"CWE-427","description":"Uncontrolled Search Path Element","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:c4851542d283095be1fad51a855e6527c0d5388e4fc9276a0e478c11bda9a928 · sha256:5da657b5af4e3f75… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"name":"Check Point Security Advisory for CVE-2026-10847","tags":["vendor-advisory"],"url":"https://support.checkpoint.com/results/sk/sk185052"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:c4851542d283095be1fad51a855e6527c0d5388e4fc9276a0e478c11bda9a928 · sha256:5da657b5af4e3f75… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.