# CVE-2026-16232 - Authentication bypass with SmartConsole login process using application token

Please read this important update from Check Point.

## Security Alert:

**High**

### Product
Multi-Domain Security Management, Security Management

### Version
R77.30 (EOS), R80 (EOS), R80.10 (EOS), R80.20 (EOS), R80.30 (EOS), R80.40 (EOS), R81 (EOS), R81.10 (EOS), R81.20, R82, R82.10

### Last Modified
2026-07-22

## Symptoms

- **Impact:** An unauthenticated attacker can obtain an application login token and use it to login via SmartConsole with full admin privileges and apply changes to the security policy and security configuration. Check Point is aware that this vulnerability is being exploited, impacting a very small number of customers.

- **Affected Products and versions**:
  - Products: Security Management Server, Multi-Domain Security Management Server (MDS)
  - Product Versions: R77.30, R80, R80.10, R80.20, R80.30, R81 R81.10, R81.20, R82, R82.10
- **Conditions:** Successful remote exploit requires **internet access** to the Management Server IP address and **no restrictions** on **Trusted Clients** (GUI clients).

- This issue received the ID [CVE-2026-16232](https://www.cve.org/CVERecord?id=CVE-2026-16232).

### Mitigation

1. Follow the [Check Point Hardening Best Practices Guide](https://sc1.checkpoint.com/documents/Check_Point_Gateway_and_Management_Hardening/CP_Check_Point_Gateway_and_Management_Hardening.pdf).

2. Limit **Trusted Clients** (GUI clients) to trusted IP addresses/subnets.
   To do so:
   1. In SmartConsole, go to **Manage & Settings** > **Permissions & Administrators** > **Trusted Clients**.
   2. Double-click the client you want to edit.
   3. In the **Trusted Client** configuration window that opens, change the settings as needed and ensure you do not use "Any" as a Type.
   4. Click **OK**.

3. Protect Management access with Firewall, restrict access to trusted IP addresses, and verify that implied rules for control connections are enabled. This will create an implied rule that will prevent management access for non-authorized IP addresses.

### How to Identify an Attack

1. In **SmartConsole**, go to **Logs & Monitor / Logs & Events**, and search for events where either the source IP or destination IP matches one of the known attacker IP addresses.

**Attacker IP addresses**
   - 151.241.99.207
   - 151.241.99.233
   - 158.62.198.182
   - 192.142.10.99
   - 139.28.37.250

**SmartConsole query**
   `(src:151.241.99.207 OR dst:151.241.99.207 OR src:151.241.99.233 OR dst:151.241.99.233 OR src:158.62.198.182 OR dst:158.62.198.182 OR src:192.142.10.99 OR dst:192.142.10.99 OR src:139.28.37.250 OR dst:139.28.37.250)`

2. In **SmartConsole**, go to **Logs & Monitor / Logs & Events** > **Audit Logs View** and search for the query "`Authentication method: application token`":

## Solution

This problem was fixed. The fix is included in:

- [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 36
- [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 118
- [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 158

## Article Properties

- Access Level: General
- Severity: High
- Status: Approved
- Date Created: 2026-07-19
- Last Modified: 2026-07-22
