CVE-2026-48136 Details
Description
When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC).
A vulnerability exists in Check Point Multi-Domain Management versions R82.10 (through Jumbo Hotfix Take 6), R82 (through Jumbo Hotfix Take 91), R81.20 (through Jumbo Hotfix Take 127), and all releases from R81.10 and below. When Compliance is enabled, an authenticated administrator with read-write access to one Management Domain can manipulate metadata related to Compliance Best Practices in another Management Domain, where they lack access permissions. This behavior bypasses Role-Based Access Control (RBAC).
To address this vulnerability, administrators should update to versions of Check Point Multi-Domain Management that include the fix: R82.10 (Jumbo Hotfix Accumulator Take 19 or above), R82 (Jumbo Hotfix Accumulator Take 103 or above), and R81.20 (Jumbo Hotfix Accumulator Take 141 or above). Additionally, it is recommended to enforce multi-factor authentication for all administrator accounts to mitigate the risk of unauthorized access.
Metrics
CVSS 4.0 Severity and Vector Strings:
No CVSS 4.0 data is available for this CVE.
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
CISA-ADP
Assessed May 26, 2026References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://support.checkpoint.com/results/sk/sk184992 | [email protected] |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-89 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') | [email protected] |
Affected Products
No affected product data is available for this CVE.
Change History
4 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jul 20, 2026 | CVE Translated | [email protected] |
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| May 26, 2026 | New CVE Received | [email protected] |