PT-2026-85223 · Checkmate · Checkmate

·

CVE-2026-85390

·

Published

2026-09-03

·

Updated

2026-09-03

CVSS v3.1

7.1

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:N/I:H/A:L
Name of the Vulnerable Software and Affected Versions Checkmate versions prior to 3.11.1
Description Checkmate omits the isAllowed role guard middleware on the 'maintenance-window', 'notification', and 'check-deletion' routes. This flaw allows users with read-only permissions to perform administrative actions, such as creating arbitrary maintenance windows to silence alerts, modifying notification channels, and deleting monitor check history to remove evidence of incidents.
Recommendations Update Checkmate to version 3.11.1 or later. As a temporary mitigation, restrict access to the 'maintenance-window', 'notification', and 'check-deletion' routes to only trusted administrative users.

Exploit

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-85390

Affected Products

Checkmate