CVE-2026-48133
Identity Awareness Captive Portal - Unauthenticated Local File Inclusion
Severity
High 7.5
CVSS 3.1
Exploited
Not listed
EPSS
0.048
91.5th percentile
Discovered by
Not disclosed
Published
May 26, 2026
Assigned by checkpoint
Description
When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.
Weakness: CWE-98
Affected products
| Vendor | Product | Category | Matched by |
|---|---|---|---|
| Check Point | Quantum Security Gateway | Firewall / NGFW | cna-assigner |
Vendor-reported products (1)
- checkpoint · Quantum Security Gateway