Beveiligingsadvies

CVE-2026-36102

CVE-kwetsbaarheidsdetails - eXtreme Datacenter Security Operations

Gepubliceerd 2026-08-27 00:00:00
Laatst bijgewerkt 2026-09-01 19:28:42
Toegewezen door mitre
CVSS-score 7.2
Status PUBLISHED

Beschrijving

An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint.