PT-2026-26654 · Checkmate · Checkmate
Theamanrawat
·
Published
2026-03-20
·
Updated
2026-03-22
·
CVE-2026-31836
CVSS v3.1
8.1
High
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
Checkmate versions prior to 3.5.1
Description
Checkmate is a self-hosted tool for tracking server hardware, uptime, response times, and incidents. A mass assignment issue exists in the user profile update endpoint, allowing authenticated users to escalate privileges to superadmin, bypassing role-based access controls. An attacker can modify their user role to gain complete administrative access, including viewing all users, modifying configurations, and accessing sensitive data. The vulnerable endpoint is the user profile update endpoint. The vulnerability allows modification of the user role through mass assignment of parameters.
Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
LPE
Improper Authorization
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Checkmate