CVE-2026-36102: Bluewave Labs Checkmate vulnerability
Published Aug 27, 2026
·Updated
An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint.
Affected Software
2 affected components
Bluewave Labs Checkmate<=3.3.0
Bluewave Labs Checkmate inviteController.js
Event History
Aug 27, 2026
CVE Published
via MITRE·12:00 AM
Data Sourced
via MITRE·12:00 AM
Description
Data Sourced
via NVD·08:17 PM
Description
Frequently Asked Questions
1
Who can exploit this issue?
An attacker must be remotely authenticated as an administrator. The vulnerable endpoint is /api/v1/invite, and exploitation uses its role parameter.
2
What privilege can an attacker obtain?
A remote authenticated administrator can escalate privileges to superadmin through the invite endpoint's role parameter.
3
Which versions are affected?
Bluewave Labs Checkmate versions up to and including 3.3.0 are affected.