Junglewise Threat Intelligence

CVE-2026-48133: Check Point Security Gateway LFI in Identity Awareness blade

CVE-2026-48133 · Severity: high · CVSS 7.5 · Published 2026-05-26

Vendors: Check Point.

Executive brief

Check Point Security Gateways using the Identity Awareness feature are vulnerable to a security flaw that allows unauthorized access to internal system files. This component is typically used to identify users and control network access via a web login page. An attacker could exploit this to steal sensitive configuration data or system information without needing any login credentials, potentially compromising the security of the network gateway.

Technical details

A Local File Inclusion (LFI) vulnerability exists in the Check Point Identity Awareness blade when Browser-Based Authentication (Captive Portal) is enabled. The vulnerability is rooted in improper control of filenames used in PHP 'include' or 'require' statements (CWE-98). A remote, unauthenticated attacker can exploit this by sending a specially crafted network request to the gateway's web interface. Successful exploitation allows the attacker to read arbitrary internal files on the Security Gateway, which may contain sensitive configuration data or system credentials. Check Point has released a security advisory (sk184993) to address this issue.

Affected products

  • Check Point Security Gateway (Identity Awareness blade)

Timeline

  • 2026-05-26: advisory: Check Point published security advisory sk184993
  • 2026-05-26: disclosed: CVE-2026-48133 published to the NVD

References