CRITICAL 9.3 NVD
CVE-2026-82042
UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a vali
UTMStack before 11.2.16 contains an authentication bypass vulnerability that allows remote attackers to gain full administrative API access by presenting a valid Utm-Internal-Key header matching the INTERNAL_KEY environment variable value, which the InternalApiKeyFilter accepts for any endpoint without path restriction, constant-time comparison, rate limiting, or audit logging. Attackers who obtain the key value can authenticate without a user account or JWT to create accounts, manage users, exfiltrate data, and modify security rules.
References
- https://github.com/UTMStack/UTMStack/releases/tag/v11.2.16
- https://github.com/utmstack/UTMStack/commit/4e7a727c3b8d8e2ad020d3b4f982a6d085dbecdd
- https://www.vulncheck.com/advisories/utmstack-authentication-bypass-via-internalapikeyfilt
This critical severity vulnerability with a CVSS score of 9.3 was published on 2026-10-02 via NVD.
Risk Timeline
CVE Disclosed2026-10-02 · 0 days ago
Remediation Resources
vulnfeed aggregates 9972 vulnerabilities from NVD, CISA KEV,
Ubuntu, Debian, Red Hat, Kubernetes, Exploit-DB, OSS-Security, GitHub and OpenStack — updated every 4 hours.