Vulnerability in Checkmate Affects Server Monitoring Tools
CVE-2026-71862
7.5HIGH
What is CVE-2026-71862?
The Checkmate tool has a vulnerability that allows unauthenticated users to access sensitive information via an API endpoint. When the global showURL setting is enabled, the unauthenticated GET /api/v1/status-page/:url endpoint can return complete monitor objects, including secret credentials that are typically hidden. This could allow attackers to extract critical information and compromise monitored services. The issue is resolved in version 3.9.2, which users are strongly encouraged to upgrade to.
Affected Version(s)
Checkmate >= 3.3.0, < 3.9.2
