> Source: [sk184993](https://support.checkpoint.com/results/sk/sk184993)

# sk184993 - CVE-2026-48133 - Identity Awareness Captive Portal - Unauthenticated Local File Inclusion

| Property | Value |
|----------|-------|
| Solution ID | sk184993 |
| Date Created | 2026-05-24 |
| Last Modified | 2026-06-25 |
| Technical Level | General |
| Products | Security Gateway, Spark Firewall (Locally Managed) |
| Versions | R82.10, R82, R81.20, R81.10 (EOS), R82.00.X, R81.10.X, R81 (EOS) |

## Symptoms

- * When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.

* This issue affects:  

  * R82.10 with Jumbo Hotfix Take 6 or below
  * R82 with Jumbo Hotfix Take 91 or below
  * R81.20 with Jumbo Hotfix Take 127 or below
  * All releases from R81.10 and below

  <br />

* This issue received the ID [CVE-2026-48133](https://www.cve.org/CVERecord?id=CVE-2026-48133)

## Solution

#### Mitigation

Keep the Identity Awareness captive portal configured as internal only (the default setting).  
To configure this setting:

1. In SmartConsole, go to the **Gateways and Servers** view.
2. Double-click the applicable Security Gateway or cluster object.
3. In the left navigation pane, select **Identity Awareness**.
4. Select **Browser-Based Authentication** , and click **Settings**.
5. Go to **Access Settings** and click **Edit**.
6. Go to**Accessibility** and click**Edit**.
7. Select **Through internal interfaces** .

   ![](https://sc1.checkpoint.com/sc/SolutionsStatics/sk184993/IDA-Browser-Based Authentication202605251235511.png)
8. Click **OK** in all windows and install policy.

#### Solution

This problem was fixed.   
For Security Gateways, the fix is included in:

* [Jumbo Hotfix Accumulator for R82.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82.10/Default.htm) starting from Take 19
* [Jumbo Hotfix Accumulator for R82](https://sc1.checkpoint.com/documents/Jumbo_HFA/R82/Default.htm) starting from Take 103
* [Jumbo Hotfix Accumulator for R81.20](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.20/Default.htm) starting from Take 141
* [Jumbo Hotfix Accumulator for R81.10](https://sc1.checkpoint.com/documents/Jumbo_HFA/R81.10/Default.htm) starting from Take 187

<br />

For Spark Firewalls, see:  

* R81.10.17 - **[sk183153](https://support.checkpoint.com/results/sk/sk183153)**
* R82.00.10 - **[sk184357](https://support.checkpoint.com/results/sk/sk184357)**

---

# Agent Instructions

This content is from the Check Point Support Center (https://support.checkpoint.com), the official knowledge base for Check Point cybersecurity products.

## Navigating This Knowledge Base

- **Complete index**: [llms.txt](https://support.checkpoint.com/llms.txt)
- **All SK articles**: [SecureKnowledge Sitemap](https://support.checkpoint.com/sitemaps/secureknowledge-sitemap-index.xml)
- **SK article URL pattern**: `https://support.checkpoint.com/results/sk/{skId}`
- **Markdown responses**: AI bot User-Agents automatically receive `text/markdown` content
