Junglewise Threat Intelligence

CVE-2026-48134: Check Point Security Gateway SQL injection in UserCheck Portal

CVE-2026-48134 · Severity: high · CVSS 7.6 · Published 2026-05-26

Executive brief

A security vulnerability exists in the Check Point UserCheck Web Portal, a tool used to notify users about corporate data policy violations. An attacker with access to the portal could manipulate or delete security incident records and interfere with the approval process for blocked data. This could lead to a loss of audit logs and disrupt the enforcement of data loss prevention policies.

Technical details

An SQL injection vulnerability (CWE-89) exists in the UserChoice flow of the Check Point UserCheck Web Portal. When the Data Loss Prevention (DLP) blade is active, the portal fails to properly sanitize input on the 'UserCheck Ask' page. A network-based attacker with low privileges can exploit this to manipulate the Security Gateway's stored incident database. Successful exploitation can result in the deletion of incident entries, incorrect processing of pending security approvals, or resource exhaustion through repeated abuse. The vulnerability is reachable via the network, though exposure is limited if the portal is not accessible from untrusted networks.

Affected products

  • Check Point Security Gateway (UserCheck Web Portal)

Timeline

  • 2026-05-26: advisory: Initial publication of CVE-2026-48134 and Check Point advisory sk184983

References

Related threats