Executive brief
Checkmate is an open-source server monitoring and uptime tracking tool. The application failed to enforce proper role-based access controls on certain administrative routes, allowing low-privilege users to create maintenance windows that silence alerts, modify notification settings, and delete monitoring check history. This enables attackers to cover up security incidents and disrupt monitoring alerting.
Technical details
The vulnerability is a broken access control (authorization bypass) in Checkmate through version 3.11.0. The affected routes (maintenance-window, notification, and check-deletion endpoints) are missing the isAllowed middleware that enforces role-based access control. While read-only and standard user-role sessions should be restricted from these administrative functions, the missing middleware allows any authenticated user to invoke them. Attackers with valid user-role credentials can create arbitrary maintenance windows to suppress alerts, modify notification channels, and delete check history to erase incident evidence. The vulnerability requires network access and valid authentication credentials. Fixes involve applying the isAllowed role guard middleware to the vulnerable routes.
Affected products
- Bluewave Labs Checkmate through 3.11.0
Timeline
- 2026-09-03: disclosed