PT-2026-23831 · Checkmate · Checkmate
Neo-Ai-Engineer
+1
·
Published
2026-03-07
·
Updated
2026-03-11
·
CVE-2026-30829
CVSS v3.1
5.3
Medium
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Checkmate versions prior to 3.4.0
Description
An unauthenticated information disclosure issue exists in the GET
/api/v1/status-page/:url endpoint. The endpoint does not enforce authentication or verify if a status page is published before revealing complete status page details. This allows any unauthenticated user to access unpublished status pages and their internal data through direct API requests. The vulnerable parameter is url.Recommendations
Update to version 3.4.0 or later.
Exploit
Fix
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Checkmate