
CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing
An authentication bypass PoC from unauthenticated network access to full administrator privileges. Single file, pure Python 3 standard library, zero dependencies.
The Management Server Java login service authenticateRemoteApplication() directly accepts the attacker-supplied SIC DN string as the identity, rather than binding it to the real DN authenticated via the TLS client certificate. By reading the Management Server's own SIC DN from unauthenticated SIC bootstrap communication and replaying it, an attacker can: forge an application identity → obtain an application token → mint a SmartConsole SSO ticket via gen-sso-token → log in with full administrator privileges.
python3 CVE-2026-16232.py --target TARGET [options]
| Parameter | Default | Description |
|---|---|---|
--target | Required | Management Server hostname or IP |
--fwm-port | 18190 | SIC/CPMI port |
--cpm-port | 19009 | CPM SOAP port |
--timeout | 10 | Network timeout (seconds) |
Application bind failed. The target is likely patched and not vulnerable.For security research, vulnerability validation, and defensive testing only. The PoC initiates SIC/CPMI authentication and token operations against the target Management Server. Use only on authorized targets or in test environments; do not run it against unauthorized systems.