sk184993 - CVE-2026-48133 - Identity Awareness Captive Portal - Unauthenticated Local File Inclusion
CVE-2026-48133 - Identity Awareness Captive Portal - Unauthenticated Local File Inclusion
Please read this important update from Check Point.
Security Alert:
- High
Product: Security Gateways, Spark Firewall
Version: R77.20 (EOS), R77.30 (EOS), R80.10 (EOS), R80.20 (EOS), R80.20.X (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, R82.10
Last Modified: 2026-06-25
Symptoms
When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.
This issue affects:
- R82.10 with Jumbo Hotfix Take 6 or below
- R82 with Jumbo Hotfix Take 91 or below
- R81.20 with Jumbo Hotfix Take 127 or below
- All releases from R81.10 and below
This issue received the ID CVE-2026-48133
Solution
Mitigation
Keep the Identity Awareness captive portal configured as internal only (the default setting).
To configure this setting:
In SmartConsole, go to the Gateways and Servers view.
Double-click the applicable Security Gateway or cluster object.
In the left navigation pane, select Identity Awareness.
Select Browser-Based Authentication, and click Settings.
Go to Access Settings and click Edit.
Go to Accessibility and click Edit.
Select Through internal interfaces.
Click OK in all windows and install policy.
Solution
This problem was fixed.
For Security Gateways, the fix is included in:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 19
- Jumbo Hotfix Accumulator for R82 starting from Take 103
- Jumbo Hotfix Accumulator for R81.20 starting from Take 141
- Jumbo Hotfix Accumulator for R81.10 starting from Take 187
For Spark Firewalls, see:
Article Properties
Access Level: General
Severity: High
Status: Approved
Date Created: 2026-05-24
Last Modified: 2026-06-25