CVE-2026-72588: bluewave-labs Checkmate - User Enumeration via Differential HTTP Response in Password Recovery
A user enumeration vulnerability in bluewave-labs/Checkmate through 2.1.0 allows an unauthenticated remote attacker to determine whether a given email address is registered. The POST /api/v1/auth/recovery/request endpoint returns HTTP 200 for registered email addresses and a different status code for unregistered ones, enabling attackers to enumerate valid user accounts.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2026-72588?
The severity of CVE-2026-72588 is rated as medium with a score of 5.3.
What type of vulnerability is CVE-2026-72588?
CVE-2026-72588 is a user enumeration vulnerability that allows attackers to verify whether an email address is registered.
How does CVE-2026-72588 impact the security of users?
CVE-2026-72588 can lead to unauthorized disclosure of registered email addresses, potentially facilitating targeted attacks.
How can I fix CVE-2026-72588?
To fix CVE-2026-72588, update to the latest version of bluewave-labs/Checkmate where the vulnerability is patched.
What is the affected software for CVE-2026-72588?
CVE-2026-72588 affects bluewave-labs Checkmate version 2.1.0 prior to the patch.