CVE-2026-72588: CWE-204: Observable Response Discrepancy in bluewave-labs Checkmate
CVE-2026-72588 is a user enumeration vulnerability in bluewave-labs Checkmate up to version 2.1.0. It allows unauthenticated remote attackers to determine if an email address is registered by observing different HTTP response codes from the password recovery endpoint. This discrepancy enables attackers to enumerate valid user accounts. The vulnerability has a medium severity with a CVSS score of 5.3.
AI Analysis
Technical Summary
The vulnerability exists in the POST /api/v1/auth/recovery/request endpoint of bluewave-labs Checkmate through version 2.1.0. When a password recovery request is made, the server returns HTTP 200 for registered email addresses and a different status code for unregistered ones. This observable response discrepancy allows an unauthenticated attacker to enumerate valid user accounts by testing email addresses. No authentication or user interaction is required to exploit this issue. The vulnerability is classified as CWE-204 (Observable Response Discrepancy).
Potential Impact
An attacker can confirm the existence of user accounts by sending requests to the password recovery endpoint and analyzing the HTTP response codes. This information disclosure can aid in targeted phishing, social engineering, or brute-force attacks. The vulnerability does not directly allow compromise of confidentiality, integrity, or availability beyond user enumeration.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider implementing uniform responses for password recovery requests regardless of email registration status to prevent user enumeration.
CVE-2026-72588: CWE-204: Observable Response Discrepancy in bluewave-labs Checkmate
Description
CVE-2026-72588 is a user enumeration vulnerability in bluewave-labs Checkmate up to version 2.1.0. It allows unauthenticated remote attackers to determine if an email address is registered by observing different HTTP response codes from the password recovery endpoint. This discrepancy enables attackers to enumerate valid user accounts. The vulnerability has a medium severity with a CVSS score of 5.3.
CVSS v3.1
Score 5.3medium
Affected software
bluewave-labs
Checkmate
Weaknesses
AI-Powered Analysis
Machine-generated threat intelligence
Technical Analysis
The vulnerability exists in the POST /api/v1/auth/recovery/request endpoint of bluewave-labs Checkmate through version 2.1.0. When a password recovery request is made, the server returns HTTP 200 for registered email addresses and a different status code for unregistered ones. This observable response discrepancy allows an unauthenticated attacker to enumerate valid user accounts by testing email addresses. No authentication or user interaction is required to exploit this issue. The vulnerability is classified as CWE-204 (Observable Response Discrepancy).
Potential Impact
An attacker can confirm the existence of user accounts by sending requests to the password recovery endpoint and analyzing the HTTP response codes. This information disclosure can aid in targeted phishing, social engineering, or brute-force attacks. The vulnerability does not directly allow compromise of confidentiality, integrity, or availability beyond user enumeration.
Mitigation Recommendations
Patch status is not yet confirmed — check the vendor advisory for current remediation guidance. Until a fix is available, consider implementing uniform responses for password recovery requests regardless of email registration status to prevent user enumeration.
Technical Details
- Data Version
- 5.2
- Assigner Short Name
- TuranSec
- Date Reserved
- 2026-08-10T10:32:53.854Z
- Cvss Version
- 3.1
- State
- PUBLISHED
Threat ID: 6a79ae70bf8831d5398afd4e
Added to database: 08/10/2026, 10:56:48 UTC
Last enriched: 08/17/2026, 15:58:33 UTC
Last updated: 09/24/2026, 03:31:04 UTC
Views: 58
Community Reviews
0 reviewsCrowdsource mitigation strategies, share intel context, and vote on the most helpful responses. Sign in to add your voice and help keep defenders ahead.
Want to contribute mitigation steps or threat intel context? Sign in or create an account to join the community discussion.
Actions
Updates to AI analysis require Pro Console access. Upgrade inside Console → Billing.
External Links
Need more coverage?
Upgrade to Pro Console for AI refresh and higher limits.
For incident response and remediation, OffSeq services can help resolve threats faster.
Latest Threats
Check if your credentials are on the dark web
Instant breach scanning across billions of leaked records. Free tier available.