GHSA-8cvg-rxfw-4pf6HighCVSS 7.1

Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window,...

Published
September 3, 2026
Last Modified
September 3, 2026

🔗 CVE IDs covered (1)

📋 Description

Checkmate through 3.11.0 omits the isAllowed role guard middleware on maintenance-window, notification, and check-deletion routes, allowing read-only users to perform administrative actions. Attackers with user-role sessions can create arbitrary maintenance windows to silence alerts, modify notification channels, and delete monitor check history to erase incident evidence.

🔗 References (8)