PT-2026-26654 · Checkmate · Checkmate

Theamanrawat

·

Published

2026-03-20

·

Updated

2026-03-22

·

CVE-2026-31836

CVSS v3.1

8.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions Checkmate versions prior to 3.5.1
Description Checkmate is a self-hosted tool for tracking server hardware, uptime, response times, and incidents. A mass assignment issue exists in the user profile update endpoint, allowing authenticated users to escalate privileges to superadmin, bypassing role-based access controls. An attacker can modify their user role to gain complete administrative access, including viewing all users, modifying configurations, and accessing sensitive data. The vulnerable endpoint is the user profile update endpoint. The vulnerability allows modification of the user role through mass assignment of parameters.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Exploit

LPE

Improper Authorization

Improper Privilege Management

Weakness Enumeration

Related Identifiers

CVE-2026-31836
GHSA-6368-X7WR-WPM2

Affected Products

Checkmate