Server-Side Request Forgery in UTMStack Affects Internal and Cloud Metadata Access
CVE-2026-82040
5.3MEDIUM
What is CVE-2026-82040?
UTMStack versions prior to 11.2.16 are vulnerable to a server-side request forgery (SSRF) that allows authenticated attackers to exploit the IdentityProviderService's validateMetadataUrl() function. By submitting a malicious metadata URL to the identity-providers endpoint, attackers can manipulate the server into making requests to arbitrary internal or cloud metadata services. This presents a significant risk, enabling potential internal network port scans and unauthorized access to sensitive instance-metadata information without proper validation of the target host or IP address.
Affected Version(s)
UTMStack 0 < 11.2.16
