Executive brief
A security flaw in Check Point Multi-Domain Management allows an authorized administrator of one domain to improperly access and modify data in other domains they are not permitted to manage. This occurs when the Compliance feature is enabled, potentially allowing an internal user to tamper with compliance metadata and bypass organizational access controls. While this requires existing administrative access, it undermines the isolation between different business units or customers managed on the same platform.
Technical details
A Role-Based Access Control (RBAC) bypass exists in Check Point Multi-Domain Management when the Compliance blade is enabled. The vulnerability is categorized as an SQL Injection (CWE-89) issue that allows an authenticated administrator with read-write privileges in one Customer Management Domain (CMA) to manipulate metadata in a different CMA. An attacker can exploit this to modify Compliance Best Practices data in domains they are not authorized to access. Exploitation requires network reachability to the management interface and high-level administrative privileges. Check Point has released a fix documented in advisory sk184992.
Affected products
- Check Point Multi-Domain Management
Timeline
- 2026-05-26: disclosed: Initial NVD publication and Check Point advisory release.