CVE-2026-48133
BaseFortify
Publication date: 2026-05-26
Last updated on: 2026-05-26
Assigner: Check Point Software Technologies Ltd.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| check_point_software_technologies | identity_awareness | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-98 | The PHP application receives input from an upstream component, but it does not restrict or incorrectly restricts the input before its usage in "require," "include," or similar functions. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability occurs when the Identity Awareness blade is enabled with Browser-Based Authentication on a Security Gateway. In this scenario, an unauthenticated user may be able to read certain internal files on the Security Gateway, which should normally be protected.
How can this vulnerability impact me? :
The impact of this vulnerability is that an unauthenticated attacker can gain access to sensitive internal files on the Security Gateway. This can lead to exposure of confidential information, potentially aiding further attacks or unauthorized access.