Skip to content
KitploitKITPLOIT
ToolsExploitsBlog
Log in
Submit
ToolsExploitsBlog
Submit

Hacking, PenTest, and Cybersecurity Tools for Your Security Arsenal!

Kitploit is a directory of hacking, cybersecurity, and pentesting tools. Discover the latest project updates to find vulnerabilities, analyze systems, automate testing, and strengthen your security.

··Feeds·Contact·Privacy·© 2026 Kitploit

Tool Directory

Categories

View all categories
Loading categories
CVE-2026-16232 — CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing | Kitploit
Tools/GitHubGitHub/hackspeak/cve-2026-16232
Authentication & AuthorizationVulnerability AnalysisExploitationPenetration Testing
GitHubhackspeak/cve-2026-16232

CVE-2026-16232

CVE-2026-16232 (Check Point SmartConsole authentication bypass) PoC - unauth to admin; for authorized security testing

View Repository
21101 month agoNot yet reviewed

Most Popular

View all →

Discover the most used tools by our community.

Explore all tools

Browse our collection of tools

View all tools →
Share

CVE-2026-16232 — Check Point SmartConsole Authentication Bypass

An authentication bypass PoC from unauthenticated network access to full administrator privileges. Single file, pure Python 3 standard library, zero dependencies.

Vulnerability Summary

The Management Server Java login service authenticateRemoteApplication() directly accepts the attacker-supplied SIC DN string as the identity, rather than binding it to the real DN authenticated via the TLS client certificate. By reading the Management Server's own SIC DN from unauthenticated SIC bootstrap communication and replaying it, an attacker can: forge an application identity → obtain an application token → mint a SmartConsole SSO ticket via gen-sso-token → log in with full administrator privileges.

  • Vulnerability ID: CVE-2026-16232
  • CVSS: 9.3 (Check Point) / 9.1 (CISA), CWE-287
  • Affected products: Security Management Server, Multi-Domain Security Management Server (MDS)
  • Exploitation status: Zero-day, exploited in the wild (added to CISA KEV on 2026-07-22)
  • Fixed versions: R81.20 Jumbo Hotfix Take 158+ / R82 Take 118+ / R82.10 Take 36+

Usage

python3 CVE-2026-16232.py --target TARGET [options]
ParameterDefaultDescription
--targetRequiredManagement Server hostname or IP
--fwm-port18190SIC/CPMI port
--cpm-port19009CPM SOAP port
--timeout10Network timeout (seconds)
  • Vulnerable target: Application bind succeeds → application token obtained → redeem a SmartConsole administrator session, enabling enumeration of all administrators;
  • Patched target: Outputs Application bind failed. The target is likely patched and not vulnerable.

⚠️ Disclaimer

For security research, vulnerability validation, and defensive testing only. The PoC initiates SIC/CPMI authentication and token operations against the target Management Server. Use only on authorized targets or in test environments; do not run it against unauthorized systems.

Attribution & References

  • Original PoC: sfewer-r7/CVE-2026-16232 (Stephen Fewer, Rapid7; the original repository declares no license), this repository is a distribution mirror
  • Rapid7 technical analysis: https://www.rapid7.com/blog/post/ra-check-point-smartconsole-authentication-bypass-technical-analysis-cve-2026-16232/
  • Check Point official advisory: https://support.checkpoint.com/results/sk/sk185169/
Download Tool