{"description":"Trending threats, MITRE ATT\u0026CK coverage, and detection metadata. Fed continuously.","favicon":"https://feed.craftedsignal.io/favicon-32x32.png","feed_url":"https://feed.craftedsignal.io/products/checkmate--3.11.0/feed.json","home_page_url":"https://feed.craftedsignal.io/","icon":"https://feed.craftedsignal.io/apple-touch-icon.png","items":[{"_cs_actors":[],"_cs_cpes":["cpe:2.3:a:checkmate:checkmate:*:*:*:*:*:*:*:*"],"_cs_cves":[{"cvss":7.1,"id":"CVE-2026-85390"}],"_cs_exploited":false,"_cs_has_poc":false,"_cs_poc_references":[],"_cs_products":["Checkmate (\u003c= 3.11.0)"],"_cs_severities":["high"],"_cs_tags":["privilege-escalation","web-application-vulnerability"],"_cs_type":"advisory","_cs_vendors":["Checkmate"],"content_html":"\u003cp\u003eCheckmate through version 3.11.0 contains an authorization bypass vulnerability (CVE-2026-85390) originating from the omission of the 'isAllowed' role guard middleware on specific administrative API routes. These affected routes include maintenance-window management, notification channel configurations, and monitor check deletion endpoints. The flaw effectively grants authenticated users with read-only privileges the ability to perform high-privilege administrative operations. By exploiting this gap in access control, an attacker can manipulate system-wide monitoring configurations, silence critical alerts by creating arbitrary maintenance windows, or modify notification delivery to suppress security event awareness. Furthermore, the ability to delete check history permits the removal of incident evidence, potentially impeding forensic investigations and post-incident response activities within affected environments.\u003c/p\u003e\n\u003ch2 id=\"impact\"\u003eImpact\u003c/h2\u003e\n\u003cp\u003eSuccessful exploitation allows read-only users to escalate their functional permissions, leading to potential loss of monitoring integrity and unauthorized removal of historical security telemetry. Organizations relying on Checkmate for infrastructure monitoring may face critical alert suppression and loss of audit trails, allowing other malicious activity to go undetected.\u003c/p\u003e\n\u003ch2 id=\"recommendation\"\u003eRecommendation\u003c/h2\u003e\n\u003col\u003e\n\u003cli\u003eUpgrade Checkmate to version 3.11.1 or later immediately to patch CVE-2026-85390.\u003c/li\u003e\n\u003cli\u003ePerform an audit of administrative activity logs, specifically targeting successful calls to maintenance-window, notification-update, or check-deletion endpoints by accounts lacking the 'Administrator' role.\u003c/li\u003e\n\u003cli\u003eReview audit logs for atypical monitor check deletion activity occurring from read-only service accounts or user sessions.\u003c/li\u003e\n\u003c/ol\u003e\n","date_modified":"2026-09-03T19:22:54Z","date_published":"2026-09-03T19:22:54Z","id":"https://feed.craftedsignal.io/briefs/2026-09-checkmate-auth-bypass/","summary":"Checkmate versions through 3.11.0 contain an authorization bypass vulnerability (CVE-2026-85390) that allows read-only users to perform unauthorized administrative actions by accessing restricted routes.","title":"Authorization Bypass in Checkmate via Missing Role Guard Middleware","url":"https://feed.craftedsignal.io/briefs/2026-09-checkmate-auth-bypass/"}],"language":"en","title":"CraftedSignal Threat Feed - Checkmate (\u003c= 3.11.0)","version":"https://jsonfeed.org/version/1.1"}