sk184993 - CVE-2026-48133 - Identity Awareness Captive Portal - Unauthenticated Local File Inclusion

CVE-2026-48133 - Identity Awareness Captive Portal - Unauthenticated Local File Inclusion

Please read this important update from Check Point.

Security Alert:

Product: Security Gateways, Spark Firewall

Version: R77.20 (EOS), R77.30 (EOS), R80.10 (EOS), R80.20 (EOS), R80.20.X (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, R82.10

Last Modified: 2026-06-25

Symptoms

Solution

Mitigation

Keep the Identity Awareness captive portal configured as internal only (the default setting).

To configure this setting:

  1. In SmartConsole, go to the Gateways and Servers view.

  2. Double-click the applicable Security Gateway or cluster object.

  3. In the left navigation pane, select Identity Awareness.

  4. Select Browser-Based Authentication, and click Settings.

  5. Go to Access Settings and click Edit.

  6. Go to Accessibility and click Edit.

  7. Select Through internal interfaces.

  8. Click OK in all windows and install policy.

Solution

This problem was fixed.

For Security Gateways, the fix is included in:

For Spark Firewalls, see:

Article Properties

Access Level: General

Severity: High

Status: Approved

Date Created: 2026-05-24

Last Modified: 2026-06-25