{"id":"CVE-2026-36102","aliases":[],"url":"https://o3.security/vulnerability/CVE-2026-36102","summary":"An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter…","details":"An issue in the inviteController.js component in Bluewave Labs Checkmate <=3.3.0 allows remote authenticated administrators to escalate privileges to superadmin via the role parameter to the /api/v1/invite endpoint.","published":"2026-08-27T20:17:40.750","modified":"2026-09-01T20:17:13.583","cvss":{"score":7.2,"severity":"HIGH","vector":"CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H"},"epss":null,"cisaKev":null,"exploitsKnown":null,"affectedPackages":[],"fix":null,"references":[{"type":"WEB","url":"https://gist.github.com/Joren2087/cc60f1c8dfe0680c1e5e867b70703e22"},{"type":"WEB","url":"https://outline.joren2087.be/s/f02631bd-cddd-4e59-952b-0e756cdc8fba"},{"type":"WEB","url":"https://gist.github.com/Joren2087/cc60f1c8dfe0680c1e5e867b70703e22"}],"provenance":{"sources":["OSV.dev","NVD","FIRST.org (EPSS)"],"lastVerified":"2026-09-01T20:17:13.583"}}