CVE-2026-48134 Details
Description
When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to disruptions such as loss of stored incident entries, incorrect handling of pending approvals, or resource impact if the issue is abused repeatedly. Exposure is reduced if the UserCheck Portal is not accessible from untrusted networks.
A vulnerability has been identified in the UserCheck Web Portal of Check Point Security Gateways, specifically in the UserChoice flow, when Data Loss Prevention (DLP) is active. This issue allows an attacker with access to the UserCheck Ask page to manipulate the Security Gateway's DLP/UserCheck incident data. Potential consequences include the loss of incident records, improper management of pending approvals, and resource strain if the vulnerability is exploited repeatedly. The risk is lower if the UserCheck Portal is not reachable from untrusted networks.
To address this vulnerability, ensure that the UserCheck Portal is only accessible through internal interfaces. This can be configured in SmartConsole under the UserCheck Accessibility settings for each Security Gateway or cluster object. The vulnerability can also be fixed by applying the appropriate Jumbo Hotfix Accumulator for the gateway version.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed Jun 2, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.checkpoint.com/results/sk/sk184983 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
5 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 24, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | CVE Modified | [email protected] |
| May 26, 2026 | New CVE Received | [email protected] |