CVE-2026-48136: Check Point Quantum Security Management

Medium severity, CVSS 4.1. EPSS: 0.3% chance of exploitation in the next 30 days.

When Compliance is enabled on Check Point Multi-Domain Management, an authenticated administrator with read-write access to one Management Domain (CMA) can modify stored metadata associated with Compliance Best Practices in another Management Domain, where the administrator has no access permissions, bypassing Role-Based Access Control (RBAC).

Affected products

  • Check Point Quantum Security Management: up to and including R82.10; up to and including R81.20; up to and including R81.10

Published 2026-05-26. Last modified 2026-07-20.