๐Ÿ” CVE Alert

CVE-2026-31836

HIGH 8.1

Mass Assignment Privilege Escalation in Checkmate

CVSS Score
8.1
EPSS Score
0.0%
EPSS Percentile
0th

Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. In versions from 3.5.1 and prior, a mass assignment vulnerability in Checkmate's user profile update endpoint allows any authenticated user to escalate their privileges to superadmin, bypassing all role-based access controls. An attacker can modify their user role to gain complete administrative access to the application, including the ability to view all users, modify critical configurations, and access sensitive system data. At time of publication, there are no publicly available patches.

CWE CWE-285 CWE-269
Vendor bluewave-labs
Product checkmate
Published Mar 20, 2026
Last Updated Mar 20, 2026
Stay Ahead of the Next One

Get instant alerts for bluewave-labs checkmate

Be the first to know when new high vulnerabilities affecting bluewave-labs checkmate are published โ€” delivered to Slack, Telegram or Discord.

Get Free Alerts โ†’ Free ยท No credit card ยท 60 sec setup

CVSS v3 Breakdown

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
None
Scope
Unchanged
Confidentiality
High
Integrity
High
Availability
None

Affected Versions

bluewave-labs / Checkmate
<= 3.5.1

References

NVD โ†— CVE.org โ†— EPSS Data โ†—
github.com: https://github.com/bluewave-labs/Checkmate/security/advisories/GHSA-6368-x7wr-wpm2