CVE-2026-48133

Identity Awareness Captive Portal - Unauthenticated Local File Inclusion

Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.048
91.5th percentile
Discovered by
Not disclosed
Published
May 26, 2026
Assigned by checkpoint

Description

When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.

Weakness: CWE-98

Affected products

Vendor Product Category Matched by
Check Point Quantum Security Gateway Firewall / NGFW cna-assigner
Vendor-reported products (1)
  • checkpoint · Quantum Security Gateway

Something wrong here?