PT-2026-104444 · Utmstack · Utmstack

·

CVE-2026-82042

·

Published

2026-10-02

·

Updated

2026-10-02

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions UTMStack versions prior to 11.2.16
Description An authentication bypass exists that allows remote attackers to obtain full administrative API access. This occurs because the InternalApiKeyFilter accepts a valid Utm-Internal-Key header matching the INTERNAL KEY environment variable for any endpoint. The implementation lacks path restrictions, constant-time comparison, rate limiting, and audit logging. Attackers possessing this key can bypass user account requirements or JSON Web Tokens (JWT) to create accounts, manage users, exfiltrate data, and modify security rules.
Recommendations Update UTMStack to version 11.2.16 or later.

Fix

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2026-82042

Affected Products

Utmstack