Check Point UserCheck Web Portal DLP Incident Management Disruption Vulnerability

Vulnerability

A vulnerability has been identified in the UserCheck Web Portal of Check Point Security Gateways, specifically in the UserChoice flow, when Data Loss Prevention (DLP) is active. This issue allows an attacker with access to the UserCheck Ask page to manipulate the Security Gateway's DLP/UserCheck incident data. Potential consequences include the loss of incident records, improper management of pending approvals, and resource strain if the vulnerability is exploited repeatedly. The risk is lower if the UserCheck Portal is not reachable from untrusted networks.

Impact

Exploitation of this vulnerability can disrupt the management of DLP/UserCheck incidents, leading to lost incident entries, mismanaged approvals, and potential resource impacts from repeated abuse.

Remediation

To address this vulnerability, ensure that the UserCheck Portal is only accessible through internal interfaces. This can be configured in SmartConsole under the UserCheck Accessibility settings for each Security Gateway or cluster object. The vulnerability can also be fixed by applying the appropriate Jumbo Hotfix Accumulator for the gateway version.

Added: May 26, 2026, 5:08 PM
Updated: May 26, 2026, 5:08 PM

Vulnerability Rating

Custom Algorithm
spread
5.7
impact
1.3
exploitability
7.0
remediation
7.9
relevance
9.1
threat
0.0
urgency
2.9
incentive
4.2

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.