Description
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Published: 2026-07-22
Score: 9.3 Critical
EPSS: 73.3% High
KEV: Yes
Impact: n/a
Action: n/a
AI Analysis

Impact

An unauthenticated remote attacker can exploit the Check Point SmartConsole login process to obtain an application login token and then use that token to authenticate with full administrative privileges. This allows the attacker to modify security policies and configurations, effectively taking complete control of the management environment. The vulnerability is classified under CWE-287 and achieves a CVSS score of 9.3, indicating a high likelihood of severe impact if exploited.

Affected Systems

The vulnerability affects Check Point products from the Multi‑Domain Security Management and Quantum Security Management lines. No specific version numbers are provided in this advisory.

Risk and Exploitability

The CVSS score of 9.3 places the flaw in the high‑severity range. The EPSS score of 73% indicates a high exploitation probability. The vulnerability is listed in the CISA KEV catalog and has been observed in a very small number of customer environments, implying that exploitation is active. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Based on the description, it is inferred that the attack vector is a remote component‑level exploit against the SmartConsole login API.

Generated by OpenCVE AI on August 11, 2026 at 23:43 UTC.

Remediation

No vendor fix or workaround currently provided.

OpenCVE Recommended Actions

  • Apply the latest Check Point SmartConsole security patch that addresses CVE-2026-16232.
  • Configure the SmartConsole login service to only allow connections from trusted IP ranges or a VPN tunnel, thereby blocking unauthenticated external access.
  • Enable multi‑factor authentication for all SmartConsole administrative accounts to add an additional barrier against compromised tokens.

Generated by OpenCVE AI on August 11, 2026 at 23:43 UTC.

Tracking

Sign in to view the affected projects.

Advisories

No advisories yet.

History

Mon, 10 Aug 2026 19:30:00 +0000


Mon, 10 Aug 2026 18:30:00 +0000

Type Values Removed Values Added
References
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Sun, 02 Aug 2026 08:00:00 +0000

Type Values Removed Values Added
Metrics cvssV4_0

{'score': 9.3, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


Mon, 27 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
First Time appeared Checkpoint
Checkpoint multi-domain Management
Checkpoint quantum Security Management
Vendors & Products Checkpoint
Checkpoint multi-domain Management
Checkpoint quantum Security Management

Wed, 22 Jul 2026 21:30:00 +0000

Type Values Removed Values Added
References
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'active', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 20:30:00 +0000

Type Values Removed Values Added
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}

ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Wed, 22 Jul 2026 19:30:00 +0000

Type Values Removed Values Added
Metrics kev

{'dateAdded': '2026-07-22T00:00:00+00:00', 'dueDate': '2026-07-25T00:00:00+00:00'}


Wed, 22 Jul 2026 14:00:00 +0000

Type Values Removed Values Added
Description An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Title Authentication Bypass in the SmartConsole Login Process Using an Application Token
Weaknesses CWE-287
References

Subscriptions

Checkpoint Multi-domain Management Multi-domain Security Management Quantum Security Management
cve-icon MITRE

Status: PUBLISHED

Assigner: checkpoint

Published:

Updated: 2026-08-10T18:34:01.548Z

Reserved: 2026-07-19T12:14:17.233Z

Link: CVE-2026-16232

cve-icon Vulnrichment

Updated: 2026-07-22T19:29:35.329Z

cve-icon NVD

Status : Analyzed

Published: 2026-07-22T14:17:15.513

Modified: 2026-08-10T19:59:12.073

Link: CVE-2026-16232

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

Updated: 2026-08-11T23:45:04Z

Weaknesses