Authentication Bypass in Check Point SmartConsole Login Process
CVE-2026-16232
Key Information:
- Vendor
Checkpoint
- Vendor
- CVE Published:
- 22 July 2026
What is CVE-2026-16232?
An authentication bypass vulnerability exists in the Check Point SmartConsole that enables an unauthenticated attacker to obtain a login token for the application. This allows the attacker to authenticate with full administrative privileges, giving them the ability to alter security policies and configurations. Successful exploitation requires internet access to the Management Server IP address at locations where Trusted Client restrictions are not enforced. Reports indicate that this vulnerability has been actively exploited, though its impact has been limited to a small number of customers.
Affected Version(s)
Multi-Domain Security Management R82.10 with Jumbo Hotfix Take 36 or below
Multi-Domain Security Management R82 with Jumbo Hotfix Take 118 or below
Multi-Domain Security Management R81.20 with Jumbo Hotfix Take 158 or below