CVE-2026-16232

CRITICAL KEV NUCLEI

Authentication Bypass in the SmartConsole Login Process Using an Application Token

Title source: cna
STIX 2.1

Exploitation Summary

CVE-2026-16232 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 22, 2026. EIP tracks 4 public exploits from researchers including HackSpeak, sfewer-r7, WadesWeaponShed. A Nuclei detection template is also available.

AI-analyzed exploit summary This PoC exploits CVE-2026-16232, an authentication bypass in Check Point SmartConsole, by abusing the SIC/CPMI service to impersonate the management server's SIC DN. It obtains an application token and mints a SmartConsole SSO ticket, granting full admin privileges without authentication.

Description

An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.

Exploits (4)

github WORKING POC 2 stars
by HackSpeak · pythonpoc
https://github.com/HackSpeak/CVE-2026-16232

This PoC exploits CVE-2026-16232, an authentication bypass in Check Point SmartConsole, by abusing the SIC/CPMI service to impersonate the management server's SIC DN. It obtains an application token and mints a SmartConsole SSO ticket, granting full admin privileges without authentication.

Classification
Working Poc 99%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Check Point Security Management Server, Multi-Domain Security Management Server (R81.20 < Take 158, R82 < Take 118, R82.10 < Take 36)
No auth needed
Prerequisites: Network access to the target's SIC/CPMI (18190) and CPM SOAP (19009) ports · Target must be running a vulnerable version of Check Point management software
mistral-large-3 · analyzed Aug 04, 2026 Full analysis →
github WORKING POC 1 stars
by HackSpeak · pythonremote
https://github.com/HackSpeak/checkpoint-smartconsole-poc

This PoC exploits CVE-2026-16232, an authentication bypass in Check Point SmartConsole, by abusing the CPMI protocol to bind an application certificate using the management server's SIC DN, then minting a SmartConsole SSO ticket to gain admin-level access without credentials. The vulnerability stems from improper validation of client-supplied `:DN` fields during certificate binding.

Classification
Working Poc 98%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Check Point SmartConsole (versions vulnerable to CVE-2026-16232)
No auth needed
Prerequisites: Network access to the target's CPMI (19009) and FWM (18190) ports · Target must be running a vulnerable version of Check Point SmartConsole
mistral-large-3 · analyzed Aug 03, 2026 Full analysis →
nomisec WORKING POC
by sfewer-r7 · remote
https://github.com/sfewer-r7/CVE-2026-16232

This PoC exploits CVE-2026-16232, an authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS). The exploit forges an application bind using the management server's SIC DN to obtain a SmartConsole administrator session token, enabling unauthorized access to sensitive data like administrator records.

Classification
Working Poc 100%
Attack Type
Auth Bypass
Complexity
Moderate
Reliability
Reliable
Target: Check Point Security Management Server and Multi-Domain Security Management Server (MDS)
No auth needed
Prerequisites: Network access to the target's SIC/CPMI port (default: 18190) and CPM SOAP port (default: 19009) · Target must be running a vulnerable version of Check Point Security Management Server or MDS
mistral-large-3 · analyzed Jul 29, 2026 Full analysis →
nomisec WORKING POC
by WadesWeaponShed · poc
https://github.com/WadesWeaponShed/Check-Point-Trusted-Access-Review

This repository contains a functional proof-of-concept tool for auditing and assessing hardening posture of Check Point management servers via the Check Point Management API. It includes server-side and client-side components to scan for misconfigurations, including CVE-2026-16232, and generate hardening reports.

Classification
Working Poc 95%
Attack Type
Other
Complexity
Moderate
Reliability
Reliable
Target: Check Point Management Server (versions affected by CVE-2026-16232)
Auth required
Prerequisites: Valid Check Point Management API credentials (username/password or API key) · Network access to the Check Point Management Server · Node.js environment to run the tool
mistral-large-3 · analyzed Jul 23, 2026 Full analysis →

Nuclei Templates (1)

Check Point Security Management Server - SmartConsole Authentication Bypass
CRITICALVERIFIEDby sfewer-r7,DhiyaneshDk
Shodan: port:18190
FOFA: port="18190"

Scores

CVSS v3 9.8
EPSS 0.7330
EPSS Percentile 99.4%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation active
Automatable yes
Technical Impact total

Details

CISA KEV 2026-07-22
VulnCheck KEV 2026-07-19
ENISA EUVD EUVD-2026-47700
CWE
CWE-287
Status published
Products (6)
checkpoint/Multi-Domain Security Management R81.10, R81, R80.30, R80.20, R80.10, R80, and R77.30
checkpoint/Multi-Domain Security Management R81.20 with Jumbo Hotfix Take 158 or below
checkpoint/Multi-Domain Security Management R82 with Jumbo Hotfix Take 118 or below
checkpoint/Multi-Domain Security Management R82.10 with Jumbo Hotfix Take 36 or below
checkpoint/multi-domain_security_management r81.20 (37 CPE variants)
checkpoint/multi-domain_security_management r82 (9 CPE variants)
Published Jul 22, 2026
KEV Added Jul 22, 2026
Tracked Since Jul 22, 2026