CVE-2026-71862
Last modified
CVE-2026-71862 is a high-severity vulnerability rated 7.5/10 on the CVSS scale. Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the unauthenticated GET /api/v1/status-page/:url endpoint to return complete monitor objects from server/src/controllers/statusPageController.ts. EPSS estimates a 0.35% chance of exploitation in the next 30 days.
Description
Checkmate is an open-source, self-hosted tool designed to track and monitor server hardware, uptime, response times, and incidents in real-time with beautiful visualizations. From 3.3.0 until 3.9.2, enabling the global showURL setting causes the unauthenticated GET /api/v1/status-page/:url endpoint to return complete monitor objects from server/src/controllers/statusPageController.ts. The response includes the secret field used by HttpProvider.ts as an HTTP Authorization credential, even though BaseStatusPage.tsx does not display that value, allowing visitors to extract credentials from the JSON response and use them against monitored services. This issue is fixed in version 3.9.2.
Metrics
Weakness Enumeration
Affected Software
Source: CNA advisory (CVE.org). NVD analysis pending.
| Vendor | Product | Versions |
|---|---|---|
| bluewave-labs | Checkmate | >= 3.3.0, < 3.9.2 |
References
Timeline
- Published
- Last Modified
- Status
- Deferred
Frequently Asked Questions
What is CVE-2026-71862?
How severe is CVE-2026-71862?
How do I fix CVE-2026-71862?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2026
- CVE-2026-71850Hono is a Web application framework that provides support fo…4.8
- CVE-2026-71851crypto-js is a JavaScript library of crypto standards. Versi…9
- CVE-2026-71852pypdf is a free and open-source pure-python PDF library. Pri…4.8
- CVE-2026-71855Suricata is a network Intrusion Detection System, Intrusion …5.9
- CVE-2026-71858Notepad++ is a free and open-source source code editor. Prio…5.4
- CVE-2026-7186Stored cross-site scripting in the URL dashboard widget in C…5.4
- CVE-2026-71864Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-71865Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-71866Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-71867Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-71868Orval generates type-safe JavaScript clients in TypeScript f…9.3
- CVE-2026-71869Orval generates type-safe JavaScript clients in TypeScript f…9.3
Are you affected by CVE-2026-71862?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
