Description
This module exploits CVE-2026-16232, an authentication bypass in the Check Point SmartConsole login process affecting Security Management Server and Multi-Domain Security Management Server. A vulnerable management server accepts a client-supplied SIC distinguished name during an application certificate bind instead of binding the application identity to the authenticated peer certificate.
The module uses the unauthenticated FWM/CPMI service to replay the management server's own SIC DN, mints a SmartConsole SSO ticket, and redeems it over the CPM SOAP service. The resulting administrative session is then used to submit a local one-time run-script command.
Affected versions include R82.10 before Jumbo Hotfix Take 36, R82 before Jumbo Hotfix Take 118, and R81.20 before Jumbo Hotfix Take 158. Older supported release families are also affected according to the vendor advisory. Exploitation requires network access to the management server (Specifically the FWM/CPMI service port on TCP 18190, and the CPM/DLE service port on TCP 19009), and a Trusted Clients configuration that does not restrict GUI clients.
This module has been successfully tested against vulnerable R82.10 and R81.20 targets.
Module options
To display the available options, load the module within the Metasploit console and run the commands 'show options' or 'show advanced':
msf > use exploit/linux/misc/checkpoint/smartconsole_cve_2026_16232_rcemsf undefined(smartconsole_cve_2026_16232_rce) > show actions ...actions...msf undefined(smartconsole_cve_2026_16232_rce) > set ACTION < action-name >msf undefined(smartconsole_cve_2026_16232_rce) > show options ...show and set options...msf undefined(smartconsole_cve_2026_16232_rce) > runPrioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub