PT-2026-79425 · Checkmate · Checkmate
CVE-2026-71862
·
Published
2026-08-21
·
Updated
2026-08-21
CVSS v3.1
7.5
High
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Checkmate versions 3.3.0 through 3.9.1
Description
Enabling the global
showURL setting allows unauthenticated users to access the 'GET /api/v1/status-page/:url' endpoint. This endpoint returns complete monitor objects from the statusPageController.ts controller, which include the secret field used by HttpProvider.ts as an HTTP Authorization credential. Although the BaseStatusPage.tsx component does not display this value in the user interface, the credential remains present in the JSON response, allowing visitors to extract it and use it against monitored services.Recommendations
Update to version 3.9.2.
Disable the
showURL setting as a temporary mitigation measure.Exploit
Fix
Insufficiently Protected Credentials
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Checkmate