A Leader in the 2026 Gartner® Magic Quadrant™ for Endpoint Protection. Six years running.Six years. Gartner® Magic Quadrant™ Leader.Find Out Why
Experiencing a Breach?Blog
Get StartedContact Us
SentinelOne
  • Platform
    Platform Overview
    • Singularity Platform
      Welcome to Integrated Enterprise Security
    • AI for Security
      Leading the Way in AI-Powered Security Solutions
    • Securing AI
      Accelerate AI Adoption with Secure AI Tools, Apps, and Agents.
    • How It Works
      The Singularity XDR Difference
    • Singularity Marketplace
      One-Click Integrations to Unlock the Power of XDR
    • Pricing & Packaging
      Comparisons and Guidance at a Glance
    Data & AI
    • Purple AI
      Accelerate SecOps with Generative AI
    • Singularity Hyperautomation
      Easily Automate Security Processes
    • AI-SIEM
      The AI SIEM for the Autonomous SOC
    • AI Data Pipelines
      Security Data Pipeline for AI SIEM and Data Optimization
    • Singularity Data Lake
      AI-Powered, Unified Data Lake
    • Singularity Data Lake for Log Analytics
      Seamlessly Ingest Data from On-Prem, Cloud or Hybrid Environments
    Endpoint Security
    • Singularity Endpoint
      Autonomous Prevention, Detection, and Response
    • Singularity XDR
      Native & Open Protection, Detection, and Response
    • Singularity RemoteOps Forensics
      Orchestrate Forensics at Scale
    • Singularity Threat Intelligence
      Comprehensive Adversary Intelligence
    • Singularity Vulnerability Management
      Application & OS Vulnerability Management
    • Singularity Identity
      Identity Threat Detection and Response
    Cloud Security
    • Singularity Cloud Security
      Block Attacks with an AI-Powered CNAPP
    • Singularity Cloud Native Security
      Secure Cloud and Development Resources
    • Singularity Cloud Workload Security
      Real-Time Cloud Workload Protection Platform
    • Singularity Cloud Data Security
      AI-Powered Threat Detection for Cloud Storage
    • Singularity Cloud Security Posture Management
      Detect and Remediate Cloud Misconfigurations
    Securing AI
    • Prompt Security
      Secure AI Tools Across Your Enterprise
  • Why SentinelOne?
    Why SentinelOne?
    • Why SentinelOne?
      Cybersecurity Built for What’s Next
    • Our Customers
      Trusted by the World’s Leading Enterprises
    • Industry Recognition
      Tested and Proven by the Experts
    • About Us
      The Industry Leader in Autonomous Cybersecurity
    Compare SentinelOne
    • Arctic Wolf
    • Broadcom
    • CrowdStrike
    • Cybereason
    • Microsoft
    • Palo Alto Networks
    • Sophos
    • Splunk
    • Trellix
    • Trend Micro
    • Wiz
    Verticals
    • Energy
    • Federal Government
    • Finance
    • Healthcare
    • Higher Education
    • K-12 Education
    • Manufacturing
    • Retail
    • State and Local Government
  • Services
    Managed Services
    • Managed Services Overview
      Wayfinder Threat Detection & Response
    • Threat Hunting
      World-Class Expertise and Threat Intelligence
    • Managed Detection & Response
      24/7/365 Expert MDR Across Your Entire Environment
    • Incident Readiness & Response
      DFIR, Breach Readiness, & Compromise Assessments
    Support, Deployment, & Health
    • Technical Account Management
      Customer Success with Personalized Service
    • SentinelOne GO
      Guided Onboarding & Deployment Advisory
    • SentinelOne University
      Live and On-Demand Training
    • Services Overview
      Comprehensive Solutions for Seamless Security Operations
    • SentinelOne Community
      Community Login
  • Partners
    Our Network
    • MSSP Partners
      Succeed Faster with SentinelOne
    • Singularity Marketplace
      Extend the Power of S1 Technology
    • Cyber Risk Partners
      Enlist Pro Response and Advisory Teams
    • Technology Alliances
      Integrated, Enterprise-Scale Solutions
    • SentinelOne for AWS
      Hosted in AWS Regions Around the World
    • Channel Partners
      Deliver the Right Solutions, Together
    • SentinelOne for Google Cloud
      Unified, Autonomous Security Giving Defenders the Advantage at Global Scale
    • Partner Locator
      Your Go-to Source for Our Top Partners in Your Region
    Partner Portal→
  • Resources
    Resource Center
    • Case Studies
    • Data Sheets
    • eBooks
    • Reports
    • Videos
    • Webinars
    • Whitepapers
    • Events
    View All Resources→
    Blog
    • Feature Spotlight
    • For CISO/CIO
    • From the Front Lines
    • Identity
    • Cloud
    • macOS
    • SentinelOne Blog
    Blog→
    Tech Resources
    • SentinelLABS
    • Ransomware Anthology
    • Cybersecurity 101
  • About
    About SentinelOne
    • About SentinelOne
      The Industry Leader in Cybersecurity
    • Investor Relations
      Financial Information & Events
    • SentinelLABS
      Threat Research for the Modern Threat Hunter
    • Careers
      The Latest Job Opportunities
    • Press & News
      Company Announcements
    • Cybersecurity Blog
      The Latest Cybersecurity Threats, News, & More
    • FAQ
      Get Answers to Our Most Frequently Asked Questions
    • DataSet
      The Live Data Platform
    • S Foundation
      Securing a Safer Future for All
    • S Ventures
      Investing in the Next Generation of Security, Data and AI
  • Pricing
Get StartedContact Us
CVE Vulnerability Database
Vulnerability Database/CVE-2026-48136

CVE-2026-48136: Check Point RBAC Bypass Vulnerability

CVE-2026-48136 is an authentication bypass flaw in Check Point Multi-Domain Management that allows administrators to modify compliance metadata across unauthorized domains, bypassing RBAC controls. This article covers the vulnerability's impact, affected systems, and available mitigations.

Published: May 28, 2026

CVE-2026-48136 Overview

CVE-2026-48136 is a Role-Based Access Control (RBAC) bypass affecting Check Point Multi-Domain Management when the Compliance feature is enabled. An authenticated administrator with read-write access to one Management Domain (Customer Management Add-on, or CMA) can modify stored metadata associated with Compliance Best Practices in a separate Management Domain where the administrator holds no permissions. The vulnerability is categorized under [CWE-89] (SQL Injection), indicating the metadata modification is achieved through improper neutralization of input used in a SQL query.

Critical Impact

Cross-domain tampering of Compliance Best Practice metadata enables an attacker with limited domain access to influence compliance posture data outside their authorized scope.

Affected Products

  • Check Point Multi-Domain Management (Provider-1 / MDS) with the Compliance blade enabled
  • Customer Management Add-on (CMA) instances managed under affected Multi-Domain deployments
  • Refer to the Check Point Security Advisory sk184992 for exact affected versions and fix availability

Discovery Timeline

  • 2026-05-26 - CVE-2026-48136 published to NVD
  • 2026-05-26 - Last updated in NVD database

Technical Details for CVE-2026-48136

Vulnerability Analysis

The flaw resides in how the Multi-Domain Management platform processes Compliance Best Practice metadata requests. When the Compliance blade is active, an administrator authenticated to a single CMA can issue requests that operate on metadata belonging to other Management Domains. The platform fails to enforce domain-scoped authorization on the affected metadata write path, breaking the tenant isolation model that Multi-Domain Management is designed to provide.

The [CWE-89] classification indicates that user-controlled input reaches a backend SQL statement without adequate parameterization or escaping. Crafted input alters the SQL query semantics so the underlying database modifies rows belonging to domains outside the attacker's authority. The attack vector is network-based but requires high privileges (an existing administrator account) and high attack complexity.

Root Cause

The root cause is improper neutralization of special elements in a SQL command combined with missing domain-context enforcement during metadata updates. The Compliance subsystem trusts the domain identifier or row selector supplied during metadata write operations rather than deriving and validating it from the authenticated session's CMA scope.

Attack Vector

An attacker first obtains valid read-write administrative credentials on any single CMA. From that authenticated session, the attacker submits crafted Compliance metadata modification requests targeting Best Practice records associated with a different Management Domain. Because the SQL layer accepts the manipulated identifiers, the write operation succeeds across the tenant boundary, resulting in low-impact tampering with confidentiality, integrity, and availability of Compliance data in the foreign domain.

No verified public proof-of-concept is available. See the Check Point Security Advisory sk184992 for technical details from the vendor.

Detection Methods for CVE-2026-48136

Indicators of Compromise

  • Unexpected modifications to Compliance Best Practice metadata in Management Domains where the acting administrator has no assigned permissions
  • Audit log entries showing Compliance metadata writes whose target domain does not match the authenticated administrator's CMA scope
  • Database-level changes to Compliance tables occurring outside scheduled compliance assessments or change windows

Detection Strategies

  • Correlate administrator session identity and assigned CMA scope against the target domain of each Compliance write operation, alerting on mismatches
  • Review SmartConsole and management server audit trails for Compliance Best Practice edits, focusing on cross-domain anomalies
  • Inspect database query logs on the management server for parameter values containing SQL meta-characters in Compliance-related statements

Monitoring Recommendations

  • Forward Multi-Domain Management audit logs to a centralized analytics platform and build alerting on cross-domain administrative actions
  • Baseline normal Compliance Best Practice editing activity per administrator, then alert on deviations in frequency or target domain
  • Monitor privileged account use on CMAs and flag sessions that interact with Compliance APIs immediately after authentication

How to Mitigate CVE-2026-48136

Immediate Actions Required

  • Apply the fix referenced in the Check Point Security Advisory sk184992 on all Multi-Domain Management servers running with Compliance enabled
  • Inventory administrative accounts on every CMA and remove read-write privileges that are not strictly required
  • Review recent Compliance Best Practice changes and revert any modifications that cannot be tied to an authorized administrator and domain

Patch Information

Check Point has published guidance and fix availability through advisory sk184992. Consult the vendor advisory for the specific Multi-Domain Management versions, jumbo hotfix takes, and upgrade paths that remediate CVE-2026-48136.

Workarounds

  • Where patching is not immediately feasible, disable the Compliance blade on Multi-Domain Management until the fix is applied, if operational requirements allow
  • Restrict administrative access to Multi-Domain Management interfaces to a hardened jump-host network segment and enforce multi-factor authentication for all CMA administrators
  • Tighten RBAC role definitions so that administrators receive only the minimum domain scope and permissions required for their duties
bash
# Configuration example: list administrator permission profiles for review
# Run from the MDS expert shell to enumerate administrators and their domain scope
mdsenv
cpmiquerybin attr "" administrators "" -a __name__,permissions_profile,permissions_scope

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

  • Vulnerability Details
  • TypeAuth Bypass

  • Vendor/TechCheck Point

  • SeverityMEDIUM

  • CVSS Score4.1

  • EPSS Probability0.04%

  • Known ExploitedNo
  • CVSS Vector
  • CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:U/C:L/I:L/A:L
  • Impact Assessment
  • ConfidentialityHigh
  • IntegrityNone
  • AvailabilityLow
  • CWE References
  • CWE-89
  • Technical References
  • Checkpoint Security Advisory
  • Related CVEs
  • CVE-2026-48135: Check Point HTTP Service DoS Vulnerability
Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.

Try SentinelOne
  • Get Started
  • Get a Demo
  • Product Tour
  • Why SentinelOne
  • Pricing & Packaging
  • FAQ
  • Contact
  • Contact Us
  • Customer Support
  • SentinelOne Status
  • Language
  • Platform
  • Singularity Platform
  • Singularity Endpoint
  • Singularity Cloud
  • Singularity AI-SIEM
  • Singularity Identity
  • Singularity Marketplace
  • Purple AI
  • Services
  • Wayfinder TDR
  • SentinelOne GO
  • Technical Account Management
  • Support Services
  • Verticals
  • Energy
  • Federal Government
  • Finance
  • Healthcare
  • Higher Education
  • K-12 Education
  • Manufacturing
  • Retail
  • State and Local Government
  • Cybersecurity for SMB
  • Resources
  • Blog
  • Labs
  • Case Studies
  • Videos
  • Product Tours
  • Events
  • Cybersecurity 101
  • eBooks
  • Webinars
  • Whitepapers
  • Press
  • News
  • Ransomware Anthology
  • Company
  • About Us
  • Our Customers
  • Careers
  • Partners
  • Legal & Compliance
  • Security & Compliance
  • Investor Relations
  • S Foundation
  • S Ventures

©2026 SentinelOne, All Rights Reserved.

Privacy Notice Terms of Use

English