CVE-2026-48133 Details
Description
When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.
A local file inclusion vulnerability has been identified in Check Point Security Gateways and Spark Firewalls when the Identity Awareness blade is enabled with Browser-Based Authentication. This issue allows an unauthenticated user to read certain internal files on the Security Gateway. The vulnerability affects multiple versions of the software, including several releases in the R81 and R82 series.
Users can mitigate this vulnerability by keeping the Identity Awareness captive portal configured as internal only, which is the default setting. For those on affected versions, the issue has been fixed in the Jumbo Hotfix Accumulator for R82.10 starting from Take 19, R82 starting from Take 103, and R81.20 starting from Take 141. Spark Firewall users can refer to sk183153 for R81.10.17 or sk184357 for R82.00.10.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.checkpoint.com/results/sk/sk184993 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-98 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | New CVE Received | [email protected] |