Zero Day MonitorZDM
DashboardVulnerabilitiesTrendingZero-DaysNewsAbout
Login
ImpressumPrivacy Policy
Zero Day Monitor © 2026
4622 articles · 179960 vulns · 37/41 feeds (7d)
← Back to list
5.6
CVE-2026-48134EXPLOITED
check point · dlp

SQL injection issue in UserCheck Portal when DLP Software Blade is active

Description

When the DLP is active, the UserCheck Web Portal contains an input-handling issue in the UserChoice flow. Under specific conditions, an attacker who can access the UserCheck Ask page could attempt to manipulate the Security Gateway's stored DLP/UserCheck incident information. This could lead to disruptions such as loss of stored incident entries, incorrect handling of pending approvals, or resource impact if the issue is abused repeatedly. Exposure is reduced if the UserCheck Portal is not accessible from untrusted networks.

Affected Products

VendorProductVersions
check pointdlpR82.10 with Jumbo Hotfix Take 6 or below, R82 with Jumbo Hotfix Take 91 or below, R81.20 with Jumbo Hotfix Take 127 or below, All releases from R81.10 and below

Also Affects

Downstream vendors/products affected by this vulnerability

VendorProductSourceConfidence
check pointsecuritycert_advisory90%

References

  • https://support.checkpoint.com/results/sk/sk184983

Related News (4 articles)

Tier D
Heise Security52d ago
IT-Sicherheitslösung Check Point Security Gateway ist verwundbar
→ No new info (linked only)
Tier B
BSI Advisories55d ago
[NEU] [hoch] Check Point Security Gateway: Mehrere Schwachstellen
→ No new info (linked only)
Tier B
CERT-FR58d ago
Multiples vulnérabilités dans les produits Check Point (27 mai 2026)
→ No new info (linked only)
Tier C
VulDB58d ago
CVE-2026-48134 | Check Point Quantum Security Gateway UserCheck Ask Page sql injection
→ No new info (linked only)
CVSS 3.15.6 MEDIUM
VectorCVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L
CISA KEV❌ No
Actively exploited✅ Yes
CWECWE-89
PublishedMay 26, 2026
Last enriched58d agov2
Trending Score0
Source articles4
Independent4
Info Completeness8/14
Missing: epss, kev, exploit, patch, iocs, mitre_attack

Community Vote

0
Login to vote
0 upvotes0 downvotes
No votes yet

Related CVEs (5)

CRITICALCVE-2026-16232EXP
Authentication Bypass in the SmartConsole Login Process Using an Application Token
Trending: 114
HIGHCVE-2026-10847EXP
Local Privilege Escalation vulnerability in Check Point Identity Agent Full for Windows OS
HIGHCVE-2026-48132
VPN service may restart unexpectedly when processing IKE traffic over NAT-T 4500/UDP
HIGHCVE-2026-48133EXP
Identity Awareness Captive Portal - Unauthenticated Local File Inclusion
HIGHCVE-2026-48135EXP
HTTP service can incorrectly process malformed HTTP requests

Pin to Dashboard

Verification

State: unverified
Confidence: 0%

Vulnerability Timeline

CVE Published
May 26, 2026
Discovered by ZDM
May 26, 2026
Updated: severity, activelyExploited
May 26, 2026
Actively Exploited
Jun 2, 2026

Version History

v2
Last enriched 58d ago
v2Tier C58d ago

Updated severity to CRITICAL and marked the vulnerability as actively exploited.

severityactivelyExploited
via VulDB
v158d ago

Initial creation