CVE-2026-36102

An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint.
Configurations

No configuration.

History

No history.

Information

Published : 2026-08-27 20:17

Updated : 2026-09-01 20:17


NVD link : CVE-2026-36102

Mitre link : CVE-2026-36102

CVE.ORG link : CVE-2026-36102


JSON object : View

Products Affected

No product.

CWE
CWE-269

Improper Privilege Management