sk184992 - CVE-2026-48136 - Authenticated Administrator Role-Based Access Control Bypass in Compliance
CVE-2026-48136 - Authenticated Administrator Role-Based Access Control Bypass in Compliance
Please read this important update from Check Point.
Security Alert:
Medium
Product: Multi-Domain Security Management
Version: R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
Last Modified: 2026-05-26
Symptoms
When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC).
The issue affects:
- R82.10 with Jumbo Hotfix Take 6 or below
- R82 with Jumbo Hotfix Take 91 or below
- R81.20 with Jumbo Hotfix Take 127 or below
- All releases from R81.10 and below
This issue received the ID CVE-2026-48136.
Solution
Mitigation
To mitigate the issue, enforce multi-factor authentication (MFA) for all administrator accounts to prevent attackers from using leaked or stolen passwords to authenticate and move laterally within the environment.
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 19
- Jumbo Hotfix Accumulator for R82 starting from Take 103
- Jumbo Hotfix Accumulator for R81.20 starting from Take 141
Article Properties
Access Level: General
Severity: Medium
Status: Approved
Date Created: 2026-05-24
Last Modified: 2026-05-26