CVE-2026-48134
BaseFortify
Publication date: 2026-05-26
Last updated on: 2026-05-26
Assigner: Check Point Software Technologies Ltd.
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| check_point_software_technologies | usercheck_portal | * |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-89 | The product constructs all or part of an SQL command using externally-influenced input from an upstream component, but it does not neutralize or incorrectly neutralizes special elements that could modify the intended SQL command when it is sent to a downstream component. Without sufficient removal or quoting of SQL syntax in user-controllable inputs, the generated SQL query can cause those inputs to be interpreted as SQL instead of ordinary user data. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability occurs in the UserCheck Web Portal when Data Loss Prevention (DLP) is active. It involves an input-handling issue in the UserChoice flow that allows an attacker who can access the UserCheck Ask page to manipulate the Security Gateway's stored DLP/UserCheck incident information.
Under specific conditions, this manipulation can lead to disruptions such as loss of stored incident entries, incorrect handling of pending approvals, or resource impact if the issue is exploited repeatedly.
How can this vulnerability impact me? :
The vulnerability can impact you by causing loss of stored incident data, which may affect your ability to track and respond to security incidents properly.
It can also lead to incorrect handling of pending approvals, potentially disrupting normal security workflows.
Repeated exploitation of this issue could cause resource impact, possibly degrading system performance or availability.
What immediate steps should I take to mitigate this vulnerability?
Exposure to this vulnerability is reduced if the UserCheck Portal is not accessible from untrusted networks.