PT-2026-43240 · Check Point · Check Point Gaia
CVE-2026-48136
·
Published
2026-05-26
·
Updated
2026-07-20
CVSS v3.1
4.1
Medium
| Vector | AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L |
Name of the Vulnerable Software and Affected Versions
Check Point Multi-Domain Management (affected versions not specified)
Description
When Compliance is enabled, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain. This allows the administrator to bypass Role-Based Access Control (RBAC), which is a method of restricting system access to authorized users based on their role within an organization, even if they have no access permissions for that specific domain.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
SQL injection
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Check Point Gaia