# CVE-2026-48133 - Identity Awareness Captive Portal - Unauthenticated Local File Inclusion

Please read this important update from Check Point.

**Security Alert:**

- **High**

**Product**: Security Gateways, Spark Firewall

**Version**: R77.20 (EOS), R77.30 (EOS), R80.10 (EOS), R80.20 (EOS), R80.20.X (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.10.X, R81.20, R82, R82.00.X, R82.10

**Last Modified**: 2026-06-25

## Symptoms

- When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.

- This issue affects:
  - R82.10 with Jumbo Hotfix Take 6 or below
  - R82 with Jumbo Hotfix Take 91 or below
  - R81.20 with Jumbo Hotfix Take 127 or below
  - All releases from R81.10 and below

- This issue received the ID [CVE-2026-48133](https://www.cve.org/CVERecord?id=CVE-2026-48133)

## Solution

#### Mitigation

Keep the Identity Awareness captive portal configured as internal only (the default setting).

To configure this setting:

1. In SmartConsole, go to the **Gateways and Servers** view.
2. Double-click the applicable Security Gateway or cluster object.
3. In the left navigation pane, select **Identity Awareness**.
4. Select **Browser-Based Authentication**, and click **Settings**.
5. Go to **Access Settings** and click **Edit**.
6. Go to **Accessibility** and click **Edit**.
7. Select **Through internal interfaces**.

8. Click **OK** in all windows and install policy.

#### Solution

This problem was fixed.

For Security Gateways, the fix is included in:

- [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 19
- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 103
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 141
- [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 187

For Spark Firewalls, see:

- R81.10.17 - **[sk183153](https://support.checkpoint.com/results/sk/sk183153)**
- R82.00.10 - **[sk184357](https://support.checkpoint.com/results/sk/sk184357)**

## Article Properties

**Access Level**: General

**Severity**: High

**Status**: Approved

**Date Created**: 2026-05-24

**Last Modified**: 2026-06-25
