<?xml version="1.0" encoding="utf-8" standalone="yes"?><rss version="2.0" xmlns:atom="http://www.w3.org/2005/Atom" xmlns:content="http://purl.org/rss/1.0/modules/content/" xmlns:webfeeds="http://webfeeds.org/rss/1.0"><channel><title>Checkmate - CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/vendors/checkmate/</link><description>Trending threats, MITRE ATT&amp;CK coverage, and detection metadata. Fed continuously.</description><generator>Hugo</generator><language>en</language><managingEditor>hello@craftedsignal.io</managingEditor><webMaster>hello@craftedsignal.io</webMaster><lastBuildDate>Thu, 03 Sep 2026 19:22:54 +0000</lastBuildDate><atom:link href="https://feed.craftedsignal.io/vendors/checkmate/feed.xml" rel="self" type="application/rss+xml"/><image><url>https://feed.craftedsignal.io/favicon-32x32.png</url><title>CraftedSignal Threat Feed</title><link>https://feed.craftedsignal.io/</link><width>32</width><height>32</height></image><webfeeds:icon>https://feed.craftedsignal.io/favicon.svg</webfeeds:icon><item><title>Authorization Bypass in Checkmate via Missing Role Guard Middleware</title><link>https://feed.craftedsignal.io/briefs/2026-09-checkmate-auth-bypass/</link><pubDate>Thu, 03 Sep 2026 19:22:54 +0000</pubDate><author>hello@craftedsignal.io</author><guid isPermaLink="true">https://feed.craftedsignal.io/briefs/2026-09-checkmate-auth-bypass/</guid><description>Checkmate versions through 3.11.0 contain an authorization bypass vulnerability (CVE-2026-85390) that allows read-only users to perform unauthorized administrative actions by accessing restricted routes.</description><content:encoded><![CDATA[<p>Checkmate through version 3.11.0 contains an authorization bypass vulnerability (CVE-2026-85390) originating from the omission of the 'isAllowed' role guard middleware on specific administrative API routes. These affected routes include maintenance-window management, notification channel configurations, and monitor check deletion endpoints. The flaw effectively grants authenticated users with read-only privileges the ability to perform high-privilege administrative operations. By exploiting this gap in access control, an attacker can manipulate system-wide monitoring configurations, silence critical alerts by creating arbitrary maintenance windows, or modify notification delivery to suppress security event awareness. Furthermore, the ability to delete check history permits the removal of incident evidence, potentially impeding forensic investigations and post-incident response activities within affected environments.</p>
<h2 id="impact">Impact</h2>
<p>Successful exploitation allows read-only users to escalate their functional permissions, leading to potential loss of monitoring integrity and unauthorized removal of historical security telemetry. Organizations relying on Checkmate for infrastructure monitoring may face critical alert suppression and loss of audit trails, allowing other malicious activity to go undetected.</p>
<h2 id="recommendation">Recommendation</h2>
<ol>
<li>Upgrade Checkmate to version 3.11.1 or later immediately to patch CVE-2026-85390.</li>
<li>Perform an audit of administrative activity logs, specifically targeting successful calls to maintenance-window, notification-update, or check-deletion endpoints by accounts lacking the 'Administrator' role.</li>
<li>Review audit logs for atypical monitor check deletion activity occurring from read-only service accounts or user sessions.</li>
</ol>
]]></content:encoded><category domain="severity">high</category><category domain="type">advisory</category><category>privilege-escalation</category><category>web-application-vulnerability</category></item></channel></rss>