PT-2026-104443 · Utmstack · Utmstack
CVSS v3.1
9.9
Critical
| Vector | AV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UTMStack versions prior to 11.2.16
Description
An authorization flaw exists in the
UTMIncidentCommandWebsocket.processCommand() function, which handles the '/command/{hostname}' STOMP destination. The system fails to perform role checks or apply a command allowlist before forwarding instructions. Consequently, any authenticated user can send arbitrary operating-system commands via gRPC to any connected agent, leading to command execution on monitored endpoints where agent processes typically operate with root or SYSTEM privileges.Recommendations
Update to version 11.2.16.
Rotate the
INTERNAL KEY.Fix
Missing Authorization
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Utmstack