sk185169 - CVE-2026-16232 - Authentication bypass with SmartConsole login process using application token
CVE-2026-16232 - Authentication bypass with SmartConsole login process using application token
Please read this important update from Check Point.
Security Alert:
High
Product
Multi-Domain Security Management, Security Management
Version
R77.30 (EOS), R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10
Last Modified
2026-07-22
Symptoms
Impact: An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration. Check Point is aware that this vulnerability is being exploited, impacting a very small number of customers.
Affected Products and versions:
- Products: Security Management Server, Multi-Domain Security Management Server (MDS)
- Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81 R81.10, R81.20, R82, R82.10
Conditions: Successful remote exploit requires internet access to the Management Server IP address and no restrictions on Trusted Clients (GUI clients).
This issue received the ID CVE-2026-16232.
Mitigation
Follow the Check Point Hardening Best Practices Guide.
Limit Trusted Clients (GUI clients) to trusted IP addresses/subnets. To do so:
- In SmartConsole, go to Manage & Settings > Permissions & Administrators > Trusted Clients.
- Double-click the client you want to edit.
- In the Trusted Client configuration window that opens, change the settings as needed and ensure you do not use "Any" as a Type.
- Click OK.
Protect Management access with Firewall, restrict access to trusted IP addresses, and verify that implied rules for control connections are enabled. This will create an implied rule that will prevent management access for non-authorized IP addresses.
How to Identify an Attack
- In SmartConsole, go to Logs & Monitor / Logs & Events, and search for events where either the source IP or destination IP matches one of the known attacker IP addresses.
Attacker IP addresses
- 151.241.99.207
- 151.241.99.233
- 158.62.198.182
- 192.142.10.99
- 139.28.37.250
SmartConsole query
(src:151.241.99.207 OR dst:151.241.99.207 OR src:151.241.99.233 OR dst:151.241.99.233 OR src:158.62.198.182 OR dst:158.62.198.182 OR src:192.142.10.99 OR dst:192.142.10.99 OR src:139.28.37.250 OR dst:139.28.37.250)
- In SmartConsole, go to Logs & Monitor / Logs & Events > Audit Logs View and search for the query "
Authentication method: application token":
Solution
This problem was fixed. The fix is included in:
- Jumbo Hotfix Accumulator for R82.10 starting from Take 36
- Jumbo Hotfix Accumulator for R82 starting from Take 118
- Jumbo Hotfix Accumulator for R81.20 starting from Take 158
Article Properties
- Access Level: General
- Severity: High
- Status: Approved
- Date Created: 2026-07-19
- Last Modified: 2026-07-22