Unauthenticated Information Disclosure in Checkmate by Bluewave Labs
CVE-2026-30829
5.3MEDIUM
What is CVE-2026-30829?
Checkmate, an open-source server management tool, prior to version 3.4.0, has an information disclosure vulnerability in the GET /api/v1/status-page/:url endpoint. This vulnerability allows unauthenticated users to access unpublished status pages and their associated internal data, as the endpoint fails to enforce authentication and doesn’t verify the publication status of the requested pages. This significant flaw can lead to unauthorized access to sensitive server monitoring information. The issue has been rectified in version 3.4.0, emphasizing the importance of upgrading to mitigate potential risks.
Affected Version(s)
Checkmate < 3.4.0
