PT-2026-104443 · Utmstack · Utmstack

·

CVE-2026-82041

·

Published

2026-10-02

·

Updated

2026-10-03

CVSS v3.1

9.9

Critical

VectorAV:N/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UTMStack versions prior to 11.2.16
Description An authorization flaw exists in the UTMIncidentCommandWebsocket.processCommand() function, which handles the '/command/{hostname}' STOMP destination. The system fails to perform role checks or apply a command allowlist before forwarding instructions. Consequently, any authenticated user can send arbitrary operating-system commands via gRPC to any connected agent, leading to command execution on monitored endpoints where agent processes typically operate with root or SYSTEM privileges.
Recommendations Update to version 11.2.16. Rotate the INTERNAL KEY.

Fix

Missing Authorization

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82041

Affected Products

Utmstack