When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC).
Advisories
No advisories yet.
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
| Link | Providers |
|---|---|
| https://support.checkpoint.com/results/sk/sk184992 |
|
History
Tue, 26 May 2026 15:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Checkpoint
Checkpoint quantum Security Management |
|
| Vendors & Products |
Checkpoint
Checkpoint quantum Security Management |
Tue, 26 May 2026 13:45:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC). | |
| Title | Authenticated Administrator Role-Based Access Control Bypass in Compliance | |
| Weaknesses | CWE-89 | |
| References |
| |
| Metrics |
cvssV3_1
|
Projects
Sign in to view the affected projects.
Status: PUBLISHED
Assigner: checkpoint
Published:
Updated: 2026-05-26T14:16:34.470Z
Reserved: 2026-05-20T19:29:00.635Z
Link: CVE-2026-48136
No data.
Status : Received
Published: 2026-05-26T14:16:39.130
Modified: 2026-05-26T14:16:39.130
Link: CVE-2026-48136
No data.
OpenCVE Enrichment
Updated: 2026-05-26T17:30:10Z
Weaknesses