Vulnerability Description
An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint.
CVSS Score
HIGH
Related Weaknesses (CWE)
References
- https://gist.github.com/Joren2087/cc60f1c8dfe0680c1e5e867b70703e22
- https://outline.joren2087.be/s/f02631bd-cddd-4e59-952b-0e756cdc8fba
- https://gist.github.com/Joren2087/cc60f1c8dfe0680c1e5e867b70703e22
FAQ
What is CVE-2026-36102?
CVE-2026-36102 is a vulnerability with a CVSS score of 7.2 (HIGH). An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/i...
How severe is CVE-2026-36102?
CVE-2026-36102 has been rated HIGH with a CVSS base score of 7.2/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2026-36102?
Check the references section above for vendor advisories and patch information. Review vendor security bulletins for remediation guidance.