๐Ÿ” CVE Alert

CVE-2026-48136

MEDIUM 4.1

Authenticated Administrator Role-Based Access Control Bypass in Compliance

CVSS Score
4.1
EPSS Score
0.0%
EPSS Percentile
0th

When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC).

CWE CWE-89
Vendor checkpoint
Product quantum security management
Published May 26, 2026
Last Updated Jun 2, 2026
Stay Ahead of the Next One

Get instant alerts for checkpoint quantum security management

Be the first to know when new medium vulnerabilities affecting checkpoint quantum security management are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
Attack Vector
Network
Attack Complexity
High
Privileges Required
High
User Interaction
None
Scope
Unchanged
Confidentiality
Low
Integrity
Low
Availability
Low

Affected Versions

checkpoint / Quantum Security Management
R82.10 with Jumbo Hotfix Take 6 or below R82 with Jumbo Hotfix Take 91 or below R81.20 with Jumbo Hotfix Take 127 or below All releases from R81.10 and below

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
support.checkpoint.com: https://support.checkpoint.com/results/sk/sk184992