CVE-2026-36102
High severity, CVSS 7.2. EPSS: 0.6% chance of exploitation in the next 30 days.
An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint.
Published 2026-08-27. Last modified 2026-09-01.