CVE-2026-16232
Received Received - Intake

Authentication Bypass in Check Point SmartConsole

Vulnerability report for CVE-2026-16232, including description, CVSS score, EPSS score, affected products, exploitability, helpful resources, and attack-flow context.

Publication date: 2026-07-22

Last updated on: 2026-07-22

Assigner: Check Point Software Technologies Ltd.

Description

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

CVSS Scores

EPSS Scores

Probability:
Percentile:

Meta Information

Published
2026-07-22
Last Modified
2026-07-22
Generated
2026-07-22
AI Q&A
2026-07-22
EPSS Evaluated
N/A
NVD
EUVD

Affected Vendors & Products

Showing 3 associated CPEs
Vendor Product Version / Range
checkpoint security_management_server *
checkpoint multi_domain_security_management_server *
checkpoint smartconsole From R77.30 (inc) to R82.10 (inc)

Helpful Resources

Exploitability

CWE
CWE Icon
KEV
KEV Icon
CWE ID Description
CWE-287 When an actor claims to have a given identity, the product does not prove or insufficiently proves that the claim is correct.

Attack-Flow Graph

AI Quick Actions

Instant insights powered by AI
Executive Summary

This is an authentication bypass vulnerability in Check Point SmartConsole that lets unauthenticated remote attackers obtain a login token and gain full admin privileges. It affects the Security Management Server and Multi-Domain Security Management Server.

Detection Guidance

Check SmartConsole logs for events involving known attacker IP addresses (151.241.99.207, 151.241.99.233, 158.62.198.182, 192.142.10.99, 139.28.37.250) or authentication via application token.

Impact Analysis

An attacker could exploit this to modify security policies, change configurations, and gain full administrative control over the affected Check Point systems. Successful exploitation requires internet access to the Management Server and no Trusted Clients restrictions.

Compliance Impact

This vulnerability allows unauthenticated attackers to gain full administrative access to security management systems, potentially compromising data integrity and confidentiality. Such unauthorized access could violate compliance requirements under GDPR and HIPAA by enabling unauthorized data access, modification, or exfiltration. Organizations using affected Check Point products may face compliance violations if the vulnerability is exploited.

Mitigation Strategies

Limit Trusted Clients to trusted IP addresses or subnets and protect management access with a firewall. Apply the latest Jumbo Hotfix Accumulators for affected versions (R82.10 Take 36+, R82 Take 118+, R81.20 Take 158+).

Chat Assistant

Ask questions about this CVE
Hi! I’m here to help you understand CVE-2026-16232. Ask me anything about the vulnerability, its impact, or mitigation strategies.
0/70

EPSS Chart