Junglewise Threat Intelligence

CVE-2026-36102: Bluewave Labs Checkmate privilege escalation in invite endpoint

CVE-2026-36102 · Severity: high · CVSS 7.2 · Published 2026-08-27

Technologies: Bluewave-Labs Checkmate. Vendors: Bluewave-Labs.

Executive brief

Checkmate is a platform for managing and monitoring infrastructure. A vulnerability in its user invitation system allows authenticated administrators to create new superuser accounts and thereby escalate their own privileges from admin to superadmin—the highest privilege level in the system. This grants access to all user accounts, sensitive data, and system-wide monitoring controls. An attacker with admin credentials could exploit this to establish persistent unauthorized control.

Technical details

The vulnerability is an authorization bypass (CWE-269, CWE-284, CWE-862) in the inviteController.js component of the POST /api/v1/invite endpoint. The vulnerable code lacks role hierarchy validation: an authenticated admin user can submit an invite token request with a role parameter set to "superadmin" without the application checking whether the requester's own role permits creation of higher-privileged accounts. The attack requires authentication (valid JWT token) and admin-level permissions. An attacker can abuse this to create a superuser account with arbitrary credentials, then use that account to gain full system access. The vulnerability is patched in version 3.4.0; affected versions are ≤3.3.0. The V2 API contains the same flaw but has not yet been patched.

Affected products

  • Bluewave Labs Checkmate <=3.3.0

Timeline

  • 2025-10-13: disclosed: Vulnerability initially reported
  • 2026-02-04: patched: Fix committed in PR 3240, released in version 3.4.0
  • 2026-08-27: advisory: CVE-2026-36102 published

References

Related threats