Authentication Bypass in Check Point SmartConsole Login Process
CVE-2026-16232

Currently unrated

What is CVE-2026-16232?

An authentication bypass vulnerability exists in the Check Point SmartConsole that enables an unauthenticated attacker to obtain a login token for the application. This allows the attacker to authenticate with full administrative privileges, giving them the ability to alter security policies and configurations. Successful exploitation requires internet access to the Management Server IP address at locations where Trusted Client restrictions are not enforced. Reports indicate that this vulnerability has been actively exploited, though its impact has been limited to a small number of customers.

Affected Version(s)

Multi-Domain Security Management R82.10 with Jumbo Hotfix Take 36 or below

Multi-Domain Security Management R82 with Jumbo Hotfix Take 118 or below

Multi-Domain Security Management R81.20 with Jumbo Hotfix Take 158 or below

References

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.