Undefined · Undefined · CVE-2026-36102
**Name of the Vulnerable Software and Affected Versions**
Bluewave Labs Checkmate versions prior to 3.3.1
**Description**
An issue in the `inviteController.js` component allows remote authenticated administrators to escalate their privileges to superadmin. This is achieved by manipulating the `role` parameter when interacting with the '/api/v1/invite' endpoint.
**Recommendations**
Update Bluewave Labs Checkmate to a version newer than 3.3.0.
Avoid using the `role` parameter in the '/api/v1/invite' endpoint until the update is applied.