Rapid7 says a SmartConsole bypass can hand attackers full admin access

cyb3rops · x · 2026-07-29

Check Point SmartConsole auth bypass can yield full admin access

Rapid7 analyzes CVE-2026-16232, an authentication bypass in Check Point SmartConsole that was disclosed on July 22, 2026.

According to the write-up, an unauthenticated attacker with network access can obtain an application login token, then use it to log in to SmartConsole with full administrator privileges. That access can be used to change security policy and configuration on the affected Security Management Server and Multi-Domain Security Management Server (MDS) environment.

The accompanying diagram shows the attack path: the attacker abuses the trust flow to obtain an application token, then exchanges it for a SmartConsole SSO ticket and admin session. Rapid7 says it also provides technical analysis and a PoC.

Original post →

More from Infra

Infra channel →