PT-2026-104444 · Utmstack · Utmstack
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
UTMStack versions prior to 11.2.16
Description
An authentication bypass exists that allows remote attackers to obtain full administrative API access. This occurs because the
InternalApiKeyFilter accepts a valid Utm-Internal-Key header matching the INTERNAL KEY environment variable for any endpoint. The implementation lacks path restrictions, constant-time comparison, rate limiting, and audit logging. Attackers possessing this key can bypass user account requirements or JSON Web Tokens (JWT) to create accounts, manage users, exfiltrate data, and modify security rules.Recommendations
Update UTMStack to version 11.2.16 or later.
Fix
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Utmstack