PT-2026-79425 · Checkmate · Checkmate

CVE-2026-71862

·

Published

2026-08-21

·

Updated

2026-08-21

CVSS v3.1

7.5

High

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
Name of the Vulnerable Software and Affected Versions Checkmate versions 3.3.0 through 3.9.1
Description Enabling the global showURL setting allows unauthenticated users to access the 'GET /api/v1/status-page/:url' endpoint. This endpoint returns complete monitor objects from the statusPageController.ts controller, which include the secret field used by HttpProvider.ts as an HTTP Authorization credential. Although the BaseStatusPage.tsx component does not display this value in the user interface, the credential remains present in the JSON response, allowing visitors to extract it and use it against monitored services.
Recommendations Update to version 3.9.2. Disable the showURL setting as a temporary mitigation measure.

Exploit

Fix

Insufficiently Protected Credentials

Information Disclosure

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-71862
GHSA-3M74-8CG9-RP8J

Affected Products

Checkmate