Unauthenticated Information Disclosure in Checkmate by Bluewave Labs
CVE-2026-30829

5.3MEDIUM

Key Information:

Status
Vendor
CVE Published:
7 March 2026

What is CVE-2026-30829?

Checkmate, an open-source server management tool, prior to version 3.4.0, has an information disclosure vulnerability in the GET /api/v1/status-page/:url endpoint. This vulnerability allows unauthenticated users to access unpublished status pages and their associated internal data, as the endpoint fails to enforce authentication and doesn’t verify the publication status of the requested pages. This significant flaw can lead to unauthorized access to sensitive server monitoring information. The issue has been rectified in version 3.4.0, emphasizing the importance of upgrading to mitigate potential risks.

Affected Version(s)

Checkmate < 3.4.0

References

CVSS V3.1

Score:
5.3
Severity:
MEDIUM
Confidentiality:
Low
Integrity:
None
Availability:
Low
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.