Back to CVE List

CVE-2026-16232

CRITICAL SEVERITY

CVSS Score & Metrics

Base Score
9.1 / 10
Vector String
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Vulnerability Description

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

Vulnerability Details

Published Date
Last Modified
CWE ID
CWE-287
Source
NVD
Vendor
checkpoint
Product
Quantum Security Management, Multi-Domain Security Management

External References

Discussion (0)

Add Comment

No comments yet. Be the first!