Quantum Security Gateway
CVE-2026-48133: Identity Awareness Captive Portal - Unauthenticated Local File Inclusion
When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.
Published
Automatic summary from the vendor's CVE record. We haven't written a full analysis of this vulnerability yet.
Affected and fixed versions
| Product / branch | Fixed in |
|---|---|
| Quantum Security Gateway R82.10 with Jumbo Hotfix Take 6 or below | See the advisory |
| Quantum Security Gateway R82 with Jumbo Hotfix Take 91 or below | See the advisory |
| Quantum Security Gateway R81.20 with Jumbo Hotfix Take 127 or below | See the advisory |
| Quantum Security Gateway All releases from R81.10 and below | See the advisory |
Always confirm against the vendor advisory, which lists every fixed hotfix.
What it is
When the Identity Awareness blade is enabled with Browser-Based Authentication, an unauthenticated user may be able to read certain internal files on the Security Gateway.
Sources
KEV status, EPSS score and vendor data refreshed automatically, last on 10 Oct 2026.