Security Advisory

CVE-2026-48136

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2026-05-26 12:57:29
Last updated 2026-06-02 14:17:00
Assigner checkpoint
CVSS score 4.1
State PUBLISHED

Description

When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC).