CVE-2026-16232
CRITICAL KEV NUCLEIAuthentication Bypass in the SmartConsole Login Process Using an Application Token
Title source: cnaExploitation Summary
CVE-2026-16232 is actively exploited and listed in the CISA Known Exploited Vulnerabilities (KEV) catalog, added July 22, 2026. EIP tracks 4 public exploits from researchers including HackSpeak, sfewer-r7, WadesWeaponShed. A Nuclei detection template is also available.
AI-analyzed exploit summary This PoC exploits CVE-2026-16232, an authentication bypass in Check Point SmartConsole, by abusing the SIC/CPMI service to impersonate the management server's SIC DN. It obtains an application token and mints a SmartConsole SSO ticket, granting full admin privileges without authentication.
Description
An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security configurations. Remote exploitation requires internet access to the Management Server IP address and a configuration that does not restrict Trusted Clients. Check Point is aware that this vulnerability is being exploited and has affected a very small number of customers.
Exploits (4)
This PoC exploits CVE-2026-16232, an authentication bypass in Check Point SmartConsole, by abusing the SIC/CPMI service to impersonate the management server's SIC DN. It obtains an application token and mints a SmartConsole SSO ticket, granting full admin privileges without authentication.
This PoC exploits CVE-2026-16232, an authentication bypass in Check Point SmartConsole, by abusing the CPMI protocol to bind an application certificate using the management server's SIC DN, then minting a SmartConsole SSO ticket to gain admin-level access without credentials. The vulnerability stems from improper validation of client-supplied `:DN` fields during certificate binding.
This PoC exploits CVE-2026-16232, an authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS). The exploit forges an application bind using the management server's SIC DN to obtain a SmartConsole administrator session token, enabling unauthorized access to sensitive data like administrator records.
This repository contains a functional proof-of-concept tool for auditing and assessing hardening posture of Check Point management servers via the Check Point Management API. It includes server-side and client-side components to scan for misconfigurations, including CVE-2026-16232, and generate hardening reports.
Nuclei Templates (1)
port:18190
port="18190"
References (2)
Scores
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H