← Back to CVE List
Vulnerability Intelligence Report
Authenticated Administrator Role-Based Access Control Bypass in Compliance

CVE-2026-48136

When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC).

No Active Exploit Signals
CVSS Base Score
4.1
MEDIUM
Exploitability:0.8
Impact Score:3.4
EPSS Probability:4.10%
Executive Threat Verdict
Evaluating...
Evaluating Threat Landscape...
Assessing known weaponization, exploitation telemetry, and federal advisories.
Attack Surface
Authentication
Weaponization
SSVC Action

Weaknesses (CWE)

CWE-89 ↗CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')

Affected Products & Versions

Vendor Product Affected Versions
checkpoint Quantum Security Management R82.10 with Jumbo Hotfix Take 6 or below (affected), R82 with Jumbo Hotfix Take 91 or below (affected), R81.20 with Jumbo Hotfix Take 127 or below (affected), All releases from R81.10 and below (affected)

References & Technical Advisories

No reference links found.

Threat Intelligence Signals

EPSS Score
4.102%

Identity & Timeline

StatusPUBLISHED
Assigning AuthorityCheck Point Software Ltd. · Vendor · Israel
Reserved2026-05-20T19:29:00
Published2026-05-26T12:57:29
Last Updated2026-06-02T14:17:00

LINK COPIED TO CLIPBOARD