CRITICAL 9.3 NVD

CVE-2026-82042

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a vali

UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtain the key value can authenticate without a user account or JWT to create accounts, manage users, exfiltrate data, and modify security rules.

References

Published: 2026-10-02 · Source: NVD · Feed updated: 2026-10-03
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-10-02 via NVD.

Risk Timeline

CVE Disclosed2026-10-02 · 0 days ago

Remediation Resources

vulnfeed aggregates 9972 vulnerabilities from NVD, CISA KEV, Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.